plugin

Visual Form Builder Vulnerabilities

18 known security issues reported for the Visual Form Builder WordPress plugin. Most recent disclosed May 2, 2022.

3 high 5 medium

Running Visual Form Builder on your site? Check whether your installed version is affected.

Scan your site free

Visual Form Builder [visual-form-builder] < 3.0.7

unknown

[en] The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
May 2, 2022

CVE-2022-1046 on NVD →

Visual Form Builder [visual-form-builder] < 3.0.8

unknown

[en] The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks

Affected:
up to 3.0.8
Fixed in:
3.0.8
Disclosed:
Apr 12, 2022

CVE-2022-0141 on NVD →

Visual Form Builder [visual-form-builder] < 3.0.7

unknown

[en] The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Apr 12, 2022

CVE-2022-0142 on NVD →

Visual Form Builder [visual-form-builder] < 3.0.7

unknown

[en] The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Apr 12, 2022

CVE-2022-0140 on NVD →

Visual Form Builder <= 3.0.7 - Cross-Site Request Forgery to Data Modification

high

The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks

CVSS:
8.8
Affected:
up to 3.0.8
Fixed in:
3.0.8
Disclosed:
Apr 11, 2022

CVE-2022-0141 on NVD →

Visual Form Builder <= 3.0.6 - Admin+ Cross-Site Scripting

medium

The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Apr 7, 2022

CVE-2022-1046 on NVD →

Visual Form Builder <= 3.0.5 - Unauthenticated Information Disclosure

medium

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

CVSS:
5.3
Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Nov 3, 2021

CVE-2022-0140 on NVD →

Visual Form Builder <= 3.0.5 - CSV Injection

medium

The Visual Form Builder WordPress plugin before 3.0.6 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

CVSS:
5.3
Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Nov 3, 2021

CVE-2022-0142 on NVD →

Visual Form Builder [visual-form-builder] < 3.0.6

unknown

[en] The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Oct 25, 2021

CVE-2021-24514 on NVD →

Visual Form Builder <= 3.0.3 - Admin+ Stored Cross-Site Scripting

medium

The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

CVSS:
4.8
Affected:
up to 3.0.3
Fixed in:
3.0.4
Disclosed:
Sep 27, 2021

CVE-2021-24514 on NVD →

Visual Form Builder <= 2.8.2 - Cross-Site Request Forgery to SQL Injection

high

The Visual Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. This is due to missing or incorrect nonce validation on the current_filter_action function. This makes it possible for unauthenticated attackers to append additional SQL queries into already...

CVSS:
8.8
Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
May 15, 2015

Visual Form Builder <= 2.8.2 - Authenticated SQL Injection

high

The Visual Form Builder plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for administrator-level attackers to append additi...

CVSS:
7.2
Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
May 15, 2015

Visual Form Builder <= 2.8.2 - Reflected Cross-Site Scripting

medium

The Visual Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

CVSS:
6.1
Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
May 15, 2015

Visual Form Builder [visual-form-builder] < 2.8.3

unknown

This plugin is prone to an SQL injection and reflected cross site scripting vulnerabilities. Update the plugin.

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
May 15, 2015

Visual Form Builder [visual-form-builder] < 2.8.3

unknown

The Visual Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
May 15, 2015

Visual Form Builder [visual-form-builder] < 2.8.3

unknown

The Visual Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. This is due to missing or incorrect nonce validation on the current_filter_action function. This makes it possible for unauthenticated attackers to append additional SQL queries into already...

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
May 15, 2015

Visual Form Builder [visual-form-builder] < 2.8.3

unknown

The Visual Form Builder plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for administrator-level attackers to append additi...

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
May 15, 2015

Visual Form Builder [visual-form-builder] < 2.8.3

unknown

The Visual Form Builder WordPress plugin was affected by a SQL Injection &amp; Reflected XSS security vulnerability.

Affected:
up to 2.8.3
Fixed in:
2.8.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database