Visual Form Builder

Visual Form Builder has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2022; all 8 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high. 2021 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (38%). Other recurring categories include Cross-Site Request Forgery (CSRF), Exposure Of Sensitive Information To An Unauthorized Actor.

Every one of the 8 issues recorded for Visual Form Builder has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, most of them (3) reported by Tim Coen. Visual Form Builder is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.0.14.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

8

Get automatic notifications for all Visual Form Builder vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2022-0141

Visual Form Builder <= 3.0.7 - Cross-Site Request Forgery to Data Modification

Read the full analysis

Vulnerability Records

8 records
Visual Form Builder banner
Latestv3.1

Visual Form Builder

Matthew Muro

Author

Matthew Muro

4.1(318)
82/100
Last Updated
2022-05-27 (4y ago)
Active Installs
20,000+
Downloads
1,734,352
Requires WP
4.7+
Requires PHP
0+
Tested up to
WP 6.0.14
Created
2011-06-23 (15y ago)

Visual Form Builder is a plugin that allows you to build and manage all kinds of forms for your website in a single place. Building a fully functional contact form takes only a few minutes and you don’t have to write one bit of PHP, CSS, or HTML! Upgrade to VFB Pro If you are a fan of Visual Form Builder and want extra features and functionality, VFB Pro is available. Features Add fields with one click Drag-and-drop reordering Simple, yet effective, logic-based anti-SPAM system Automatically stores form entries in your WordPress database Manage form entries in the WordPress dashboard Export entries to a CSV file Send form submissions to multiple emails jQuery Form Validation Customized Confirmation Messages Redirect to a WordPress Page or a URL Confirmation Email Receipt to User Standard Fields Required Fields Shortcode works on any Post or Page Embed Multiple Forms on a Post/Page One-click form duplication. Copy a form you’ve already built to save time Use your own CSS (if you want) Multiple field layout options. Arrange your fields in two, three, or a mixture of columns. Field Types Fieldset Section (group fields within a fieldset) Text input (single line) Textarea (multiple lines) Checkbox Radio (multiple choice) Select dropdown Address (street, city, state, zip, country) Date (uses jQuery UI Date Picker) Email URL Currency Number Time (12 or 24 hour format) Phone (US and International formats) HTML File Upload Instructions (plain or HTML-formatted text) Entries Manage submitted entries in WordPress dashboard Bulk Export to CSV Bulk Delete Advanced Filtering Search across all entries Collect submitted data as well as date submitted and IP Address Disable saving of all entries (GDPR) Customized Confirmation Messages Control what is displayed after a user submits a form Display HTML-formatted text Redirect to a WordPress Page Redirect to a custom URL Notification Emails Send a customized email to the user after a user submits a form Additional HTML-formatted text to be included in the body of the email Automatically include a copy of the user’s entry SPAM Protection Automatically included on every form Uses a simple and accessible, yet effective, text CAPTCHA verification system

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C