Visual Form Builder [visual-form-builder] < 3.0.7
unknown
[en] The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- May 2, 2022
CVE-2022-1046 on NVD →
Visual Form Builder [visual-form-builder] < 3.0.8
unknown
[en] The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Apr 12, 2022
CVE-2022-0141 on NVD →
Visual Form Builder [visual-form-builder] < 3.0.7
unknown
[en] The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Apr 12, 2022
CVE-2022-0142 on NVD →
Visual Form Builder [visual-form-builder] < 3.0.7
unknown
[en] The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Apr 12, 2022
CVE-2022-0140 on NVD →
Visual Form Builder <= 3.0.7 - Cross-Site Request Forgery to Data Modification
high
The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks
- CVSS:
- 8.8
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Apr 11, 2022
CVE-2022-0141 on NVD →
Visual Form Builder <= 3.0.6 - Admin+ Cross-Site Scripting
medium
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Apr 7, 2022
CVE-2022-1046 on NVD →
Visual Form Builder <= 3.0.5 - Unauthenticated Information Disclosure
medium
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
- CVSS:
- 5.3
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Nov 3, 2021
CVE-2022-0140 on NVD →
Visual Form Builder <= 3.0.5 - CSV Injection
medium
The Visual Form Builder WordPress plugin before 3.0.6 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- CVSS:
- 5.3
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Nov 3, 2021
CVE-2022-0142 on NVD →
Visual Form Builder [visual-form-builder] < 3.0.6
unknown
[en] The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Oct 25, 2021
CVE-2021-24514 on NVD →
Visual Form Builder <= 3.0.3 - Admin+ Stored Cross-Site Scripting
medium
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.4
- Disclosed:
- Sep 27, 2021
CVE-2021-24514 on NVD →
Visual Form Builder <= 2.8.2 - Cross-Site Request Forgery to SQL Injection
high
The Visual Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. This is due to missing or incorrect nonce validation on the current_filter_action function. This makes it possible for unauthenticated attackers to append additional SQL queries into already...
- CVSS:
- 8.8
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- May 15, 2015
Visual Form Builder <= 2.8.2 - Authenticated SQL Injection
high
The Visual Form Builder plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for administrator-level attackers to append additi...
- CVSS:
- 7.2
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- May 15, 2015
Visual Form Builder <= 2.8.2 - Reflected Cross-Site Scripting
medium
The Visual Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- CVSS:
- 6.1
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- May 15, 2015
Visual Form Builder [visual-form-builder] < 2.8.3
unknown
This plugin is prone to an SQL injection and reflected cross site scripting vulnerabilities.
Update the plugin.
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- May 15, 2015
Visual Form Builder [visual-form-builder] < 2.8.3
unknown
The Visual Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- May 15, 2015
Visual Form Builder [visual-form-builder] < 2.8.3
unknown
The Visual Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. This is due to missing or incorrect nonce validation on the current_filter_action function. This makes it possible for unauthenticated attackers to append additional SQL queries into already...
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- May 15, 2015
Visual Form Builder [visual-form-builder] < 2.8.3
unknown
The Visual Form Builder plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for administrator-level attackers to append additi...
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- May 15, 2015
Visual Form Builder [visual-form-builder] < 2.8.3
unknown
The Visual Form Builder WordPress plugin was affected by a SQL Injection & Reflected XSS security vulnerability.
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database