CVE-2022-0142

CVE-2022-0142: Visual Form Builder < 3.0.6 - CSV Injection

Vendor Unknown
Product Visual Form Builder
Weakness CWE-1236
Published April 12, 2022
Last update August 2, 2024

CVSS base score

—

What the vulnerability does

01Description

The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

Key dates

02Disclosure timeline

April 12, 2022 CVE published
August 2, 2024 Record updated