'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-03-30 | |
| Rule Name: | WordPress Visual Form Builder Information Disclosure Vulnerability (CVE-2022-0140) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | WordPress and WordPress plugins are products of the WordPress Foundation. WordPress is a blogging platform developed using PHP. It supports the deployment of personal blog websites on servers with PHP and MySQL. A WordPress plugin is an application add-on. The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint. | |
| Impact: | An attacker can obtain sensitive information via a successful exploit in the context of the vulnerable software. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | CVE-2022-0140 |
|
| Solutions |
|---|
| Please refer to announcements or patches release by the vendor:https://wpscan.com/vulnerability/9fa2b3b6-2fe3-40f0-8f71-371dd58fe336 |