S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2022-0140 Scanner

Detects 'Improper Access Control' vulnerability in Visual Form Builder plugin for Wordpress affects v. before 3.0.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0140
5.3
CVSS

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Visual Form Builder
AFFECTED< 3.0.6SAFE ✓≥ 3.0.6
Updated Aug 22, 2026View on NVD →
Detail

The Visual Form Builder plugin for WordPress is a popular tool for creating custom forms on websites. With this plugin, users can easily create forms for contact, surveys, registration, and much more. It is a versatile tool that simplifies the process of form creation and allows users to customize their forms to match their website's design aesthetic.

CVE-2022-0140 is a vulnerability that was detected in the Visual Form Builder plugin. This vulnerability allows unauthenticated users to view and export form entries through the vfb-export endpoint. This means that anyone can access the forms and export them as a CSV file without any restrictions or authentication process. As a result, sensitive data such as email addresses, phone numbers, and other personal information can be easily accessed and exploited by unauthorized individuals.

When exploited, this vulnerability can lead to data breaches, resulting in the loss of confidential data, reputational damage, and potential legal consequences. The unauthorized access to sensitive personal information can be devastating for individuals and businesses alike, leading to identity theft, financial fraud, and other malicious activities.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. By subscribing to the platform, users can receive actionable insights into potential threats and vulnerabilities, allowing them to take proactive steps to protect their websites and online assets. With s4e.io, users can enjoy peace of mind knowing that their digital assets are protected against potential security threats and vulnerabilities.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that users take the following precautions:

  • Immediately update the Visual Form Builder plugin to version 3.0.6 or higher to prevent unauthorized access to form entries.
  • Ensure that the plugin is properly configured to restrict access to form exports and other sensitive data. 
  • Use strong passwords and two-factor authentication for all user accounts associated with the plugin.
  • Regularly monitor website activity and check for any suspicious activity or unauthorized access to form entries.
  • Consider implementing additional security measures, such as a web application firewall or security plugin, to further enhance website security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0140 scanner - Improper Access Control vulnerability in Visual Form Builder plugin for Wordpress | S4E