PT-2022-12990 · WordPress · Visual Form Builder

Vishnupriya Ilango

·

Published

2022-04-12

·

Updated

2023-08-02

·

CVE-2022-0140

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Visual Form Builder WordPress plugin versions prior to 3.0.6
Description The issue allows unauthenticated users to see form entries or export them as a CSV file due to a lack of access control on entry form export. This can be done using the "vfb-export" endpoint.
Recommendations For versions prior to 3.0.6, update to version 3.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "vfb-export" endpoint until a patch is applied.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-0140

Affected Products

Visual Form Builder