First published: Mon May 02 2022(Updated: )
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vfbpro Visual Form Builder | <3.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-1046.
The severity of CVE-2022-1046 is medium (4.8).
The affected software for CVE-2022-1046 is the Visual Form Builder WordPress plugin before version 3.0.7.
The CWE category of CVE-2022-1046 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
To fix CVE-2022-1046, you should update the Visual Form Builder WordPress plugin to version 3.0.7 or later.