ZeroHour

CVE-2022-0140

PoC
CVSS 3.1
5.3 medium
EPSS
4%p90
Published
()
Modified
Description

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

Vendors
vfbpro
Products
visual form builder
Ecosystems
WordPress
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.