5.3
CVE-2022-0140
- EPSS 9.63%
- Veröffentlicht 12.04.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:37:59
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Visual Form Builder <= 3.0.5 - Unauthenticated Information Disclosure
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
Mögliche Gegenmaßnahme
Visual Form Builder: Update to version 3.0.6, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Visual Form Builder
Version
[*, 3.0.6)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vfbpro ≫ Visual Form Builder SwPlatformwordpress Version < 3.0.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.63% | 0.926 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.