Vulnerability Description
The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a CSRF attack, and put Cross-Site Scripting payloads in them.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Formbuilder Project | Formbuilder | <= 1.08 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/114c0202-39f8-4748-ac0d-013d2d6f02f7ExploitThird Party Advisory
- https://wpscan.com/vulnerability/114c0202-39f8-4748-ac0d-013d2d6f02f7ExploitThird Party Advisory
FAQ
What is CVE-2022-0830?
CVE-2022-0830 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, ...
How severe is CVE-2022-0830?
CVE-2022-0830 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0830?
Check the references section above for vendor advisories and patch information. Affected products include: Formbuilder Project Formbuilder.