CVE-2022-0140

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vfbpro:visual_form_builder:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:37

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9fa2b3b6-2fe3-40f0-8f71-371dd58fe336 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/9fa2b3b6-2fe3-40f0-8f71-371dd58fe336 - Exploit, Third Party Advisory
References () https://www.fortiguard.com/zeroday/FG-VD-21-082 - Third Party Advisory () https://www.fortiguard.com/zeroday/FG-VD-21-082 - Third Party Advisory

24 Jul 2023, 10:15

Type Values Removed Values Added
Summary The Visual Form Builder WordPress plugin before 3.0.8 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint. The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

20 Jul 2023, 18:12

Type Values Removed Values Added
CWE CWE-200 CWE-306
References (MISC) https://www.fortiguard.com/zeroday/FG-VD-21-082 - (MISC) https://www.fortiguard.com/zeroday/FG-VD-21-082 - Third Party Advisory

13 Jun 2022, 13:15

Type Values Removed Values Added
References
  • (MISC) https://www.fortiguard.com/zeroday/FG-VD-21-082 -
Summary The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint. The Visual Form Builder WordPress plugin before 3.0.8 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

19 Apr 2022, 18:42

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
References (MISC) https://wpscan.com/vulnerability/9fa2b3b6-2fe3-40f0-8f71-371dd58fe336 - (MISC) https://wpscan.com/vulnerability/9fa2b3b6-2fe3-40f0-8f71-371dd58fe336 - Exploit, Third Party Advisory
CPE cpe:2.3:a:vfbpro:visual_form_builder:*:*:*:*:*:wordpress:*:*

12 Apr 2022, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-12 12:15

Updated : 2024-11-21 06:37


NVD link : CVE-2022-0140

Mitre link : CVE-2022-0140

CVE.ORG link : CVE-2022-0140


JSON object : View

Products Affected

vfbpro

  • visual_form_builder
CWE
CWE-306

Missing Authentication for Critical Function