WordPress Visual Form Builder plugin before 3.0.8 contains a information disclosure vulnerability. The plugin does not perform access control on entry form export, allowing an unauthenticated user to export the form entries as CSV files using the vfb-export endpoint.
View the template here CVE-2022-0140.yaml
References:
https://github.com/ARPSyndicate/cvemon