Описание
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.6 (исключая)
cpe:2.3:a:vfbpro:visual_form_builder:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 93%
0.09629
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 5.3
github
почти 4 года назад
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
EPSS
Процентиль: 93%
0.09629
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-306