First published: Tue Apr 12 2022(Updated: )
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vfbpro Visual Form Builder | <3.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-0140.
The severity of CVE-2022-0140 is medium with a severity value of 5.3.
The Visual Form Builder WordPress plugin vulnerability allows unauthenticated users to see the form entries or export them as a CSV File using the vfb-export endpoint.
The affected software version is Visual Form Builder WordPress plugin version up to and excluding 3.0.6.
To fix the Visual Form Builder WordPress plugin vulnerability, update to version 3.0.6 or above.