WordPress.Visual.Form.Builder.Plugin.Trash.CSRF

description-logoDescription

This indicates an attack attempt to exploit a CSRF vulnerability in Visual Form Builder plugin for WordPress.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application while handling maliciously crafted requests. An attacker can exploit this by tricking an unsuspecting admin user into performing unauthorized actions

affected-products-logoAffected Products

Visual Form Builder 3.0.7 and below

Impact logoImpact

Information Spoofing: Remote attackers can serve spoof contents to unsuspecting targets.

recomended-action-logoRecommended Actions

Upgrade to Visual Form Builder 3.0.8 or higher.
https://wordpress.org/plugins/visual-form-builder/#developers

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2022-06-20 21.341 Default_action:pass:drop
2022-06-09 21.336