CVE-2022-0140
Visual Form Builder < 3.0.6 - Unauthenticated Information Disclosure
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
Productos afectados
Unknown · Visual Form Builder¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →