WordPress.Visual.Form.Builder.Plugin.Trash.CSRF
Description
This indicates an attack attempt to exploit a CSRF vulnerability in Visual Form Builder plugin for WordPress.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application while handling maliciously crafted requests. An attacker can exploit this by tricking an unsuspecting admin user into performing unauthorized actions
Affected Products
Visual Form Builder 3.0.7 and below
Impact
Information Spoofing: Remote attackers can serve spoof contents to unsuspecting targets.
Recommended Actions
Upgrade to Visual Form Builder 3.0.8 or higher.
https://wordpress.org/plugins/visual-form-builder/#developers
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |