CVE-2022-0830 Information

Description

The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms and does not sanitise as well as escape its form field values. As a result attackers could make logged in admin update and delete arbitrary forms via a CSRF attack and put Cross-Site Scripting payloads in them.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Reference

https://wpscan.com/vulnerability/114c0202-39f8-4748-ac0d-013d2d6f02f7

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

6.5

Share on: