vulnerability

WordPress Plugin: visual-form-builder: CVE-2022-0140: Exposure of Sensitive Information to an Unauthorized Actor

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Nov 3, 2021
Added
May 15, 2025
Modified
Jun 24, 2025

Description

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

Solution

visual-form-builder-plugin-cve-2022-0140
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.