The Visual Form Builder WordPress plugin prior to 3.0.8 does not enforce nonce checks which could allow malicious users to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
vfbpro visual form builder |