.. / CVE-2022-0140

Exploit for WordPress Visual Form Builder <3.0.8 - Information Disclosure (CVE-2022-0140)

Description:

WordPress Visual Form Builder plugin before 3.0.8 contains a information disclosure vulnerability. The plugin does not perform access control on entry form export, allowing an unauthenticated user to export the form entries as CSV files using the vfb-export endpoint.

Nuclei Template

View the template here CVE-2022-0140.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0140.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/cve-2022-0140
https://www.fortiguard.com/zeroday/FG-VD-21-082
https://github.com/ARPSyndicate/kenzer-templates
https://wpscan.com/vulnerability/9fa2b3b6-2fe3-40f0-8f71-371dd58fe336