Visual Form Builder <= 3.0.5 - Unauthenticated Information Disclosure
2021-11-03 00:00
Vishnupriya IlangoStrategic Overview
StatusPatched in 3.0.6
Affected PluginVisual Form Builder
Affected Version
< 3.0.6CVSS5.3Medium
CVE
CVE-2022-0140Vulnerability Overview
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
Technical Analysis
REMEDIATION: Update to version 3.0.6, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C