PT-2022-12992 · WordPress · Visual Form Builder

Vishnupriya Ilango

·

Published

2022-04-12

·

Updated

2022-06-13

·

CVE-2022-0142

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Visual Form Builder WordPress plugin versions prior to 3.0.8
Description The issue allows a user with low-level or no privileges to inject a command into the exported CSV file, potentially leading to code execution. This is achieved through CSV injection.
Recommendations For versions prior to 3.0.8, update to version 3.0.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the CSV export feature until the update is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0142

Affected Products

Visual Form Builder