Wpvibes

Form Vibes

3 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Published 05.09.2024 09:15:04
  • Last modified 11.09.2024 16:33:17

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the fv_export_csv, reset_settings, save_settings, save_columns_settings, get_a...

  • EPSS 0.76%
  • Published 12.07.2024 13:15:21
  • Last modified 10.07.2025 17:59:06

The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all versions up to, and including, 1.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e...

Exploit
  • EPSS 0.48%
  • Published 16.01.2024 16:15:10
  • Last modified 21.11.2024 07:20:12

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.