CVE-2022-0140
12.04.2022, 12:15
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
vfbpro | visual_form_builder | 𝑥 < 3.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration