CVE-2022-0140

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vfbpro:visual_form_builder:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:37

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9fa2b3b6-2fe3-40f0-8f71-371dd58fe336 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/9fa2b3b6-2fe3-40f0-8f71-371dd58fe336 - Exploit, Third Party Advisory
References () https://www.fortiguard.com/zeroday/FG-VD-21-082 - Third Party Advisory () https://www.fortiguard.com/zeroday/FG-VD-21-082 - Third Party Advisory

07 Nov 2023, 03:41

Type Values Removed Values Added
CWE CWE-306

24 Jul 2023, 10:15

Type Values Removed Values Added
Summary The Visual Form Builder WordPress plugin before 3.0.8 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint. The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

20 Jul 2023, 18:12

Type Values Removed Values Added
CWE CWE-200 CWE-306

Information

Published : 2022-04-12 12:15

Updated : 2024-11-21 06:37


NVD link : CVE-2022-0140

Mitre link : CVE-2022-0140

CVE.ORG link : CVE-2022-0140


JSON object : View

Products Affected

vfbpro

  • visual_form_builder
CWE
CWE-306

Missing Authentication for Critical Function