CVE-2022-0141

HIGH

Visual Form Builder < 3.0.6 - Cross-Site Request Forgery via Missing Nonce Check

Title source: llm
STIX 2.1

Description

The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.fortiguard.com/zeroday/FG-VD-21-081

Scores

CVSS v3 8.1
EPSS 0.0045
EPSS Percentile 36.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
vfbpro/visual_form_builder < 3.0.6
Published Apr 12, 2022
Tracked Since Feb 18, 2026