The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NVfbpro Visual Form Builder
APPVfbpro< 3.0.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2022-0142CRITICAL9.8PL ✓same product
CSV Injection w pluginie Visual Form Builder dla WordPress
CVE-2022-0141HIGH8.1same product
The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attacker...
CVE-2022-1046MEDIUM4.8same product
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field...
CVE-2021-24514MEDIUM4.8same product
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high...
CVE-2023-47518HIGH7.1same vendor
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Matthew Muro Restrict Categories plugin <= 2.6.4...