Extension WordPress
Vulnérabilités Visual Form Builder
Cette page rassemble les failles publiées pour Visual Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Visual Form Builder
8 fiches
Visual Form Builder <= 3.0.7 – Cross-Site Request Forgery to Data Modification
The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks
[*, 3.0.8)
3.0.8
11/04/2022
Visual Form Builder <= 3.0.6 – Admin+ Cross-Site Scripting
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
[*, 3.0.7)
3.0.7
07/04/2022
Visual Form Builder <= 3.0.5 – CSV Injection
The Visual Form Builder WordPress plugin before 3.0.6 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible…
[*, 3.0.6)
3.0.6
03/11/2021
Visual Form Builder <= 3.0.5 – Unauthenticated Information Disclosure
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
[*, 3.0.6)
3.0.6
03/11/2021
Visual Form Builder <= 3.0.3 – Admin+ Stored Cross-Site Scripting
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
*-3.0.3
3.0.4
27/09/2021
Visual Form Builder <= 2.8.2 – Authenticated SQL Injection
The Visual Form Builder plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
[*, 2.8.3)
2.8.3
15/05/2015
Visual Form Builder <= 2.8.2 – Cross-Site Request Forgery to SQL Injection
The Visual Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. This is due to missing or incorrect nonce validation on the current_filter_action function. This makes it possible for…
[*, 2.8.3)
2.8.3
15/05/2015
Visual Form Builder <= 2.8.2 – Reflected Cross-Site Scripting
The Visual Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 2.8.3)
2.8.3
15/05/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.