CVE-2022-0140
EUVD-2022-1535312.04.2022, 12:15
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vfbpro | visual_form_builder | 𝑥 < 3.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration