First published: Tue Apr 12 2022(Updated: )
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vfbpro Visual Form Builder | <3.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0142 is a vulnerability in the Visual Form Builder WordPress plugin before version 3.0.8 that allows CSV injection and possible code execution.
CVE-2022-0142 has a severity rating of 9.8 (critical).
CSV injection is a vulnerability where an attacker injects malicious code into a CSV file, which can lead to code execution on the server or client-side when the file is opened or imported.
An attacker with low level or no privileges can inject a command in the Visual Form Builder WordPress plugin before version 3.0.8, which will be included in the exported CSV file and may lead to code execution.
To fix CVE-2022-0142, update the Visual Form Builder WordPress plugin to version 3.0.8 or later.