The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NVfbpro Visual Form Builder
APPVfbpro< 3.0.6
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2022-0142CRITICAL9.8PL ✓ten sam produkt
CSV Injection w pluginie Visual Form Builder dla WordPress
CVE-2022-0141HIGH8.1ten sam produkt
The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attacker...
CVE-2022-1046MEDIUM4.8ten sam produkt
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field...
CVE-2021-24514MEDIUM4.8ten sam produkt
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high...
CVE-2023-47518HIGH7.1ten sam vendor
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Matthew Muro Restrict Categories plugin <= 2.6.4...