CVE-2022-0830

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
04/04/2022
Last modified:
03/06/2022

Description

The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a CSRF attack, and put Cross-Site Scripting payloads in them.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:formbuilder_project:formbuilder:*:*:*:*:*:wordpress:*:* 1.08 (including)