CVE Database
/

CVE-2022-0140

Back to search

CVE-2022-0140

Published: Apr 12, 2022

Modified: Aug 2, 2024

PUBLISHED

Description

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

VendorProductVersions

Unknown

Visual Form Builder

affected
0 - < 3.0.6

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now