CyberSec.Space Logo
CVEブラウザに戻る

CVE-2017-20192

HIGH
8.3
CVSS Severity Score
EPSS Score0.1640%
EPSS Percentile11.50th
Published2024年10月16日
Last Modified2025年12月23日

Vulnerability Description

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected Platforms (CPE)

📦
Strategy11

Formidable Form Builder

< 2.05.03

References & Advisories

関連する脆弱性情報