CVE-2022-0141
HIGHVisual Form Builder < 3.0.6 - Cross-Site Request Forgery via Missing Nonce Check
Title source: llmDescription
The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/2adc8390-bb19-4adf-9805-e9c462d14d22
Vendor Advisory x_refsource_misc
https://www.fortiguard.com/zeroday/FG-VD-21-081
Scores
CVSS v3
8.1
EPSS
0.0045
EPSS Percentile
36.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (1)
vfbpro/visual_form_builder
< 3.0.6
Published
Apr 12, 2022
Tracked Since
Feb 18, 2026