Vfbpro maintains a focused WordPress plugin portfolio centered on form-building and access-control tools, where the modest disclosure volume belies a critical-severity tendency and frequent public exploit availability reflecting the security-sensitive role these plugins play in user data collection and authentication. The recurring vulnerability classes—cross-site scripting, cross-site request forgery, CSV-formula injection, and missing authentication on administrative functions—are characteristic of web-form handling and privilege-boundary issues in WordPress plugin development. Defenders should prioritize updates for these plugins in WordPress installations and audit form endpoints for input-validation and CSRF protections; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vfbpro over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0142CRITICAL The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in th | Apr 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-0140MEDIUM The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a | Apr 12, 2022 | 5.3 | 31 | NO | YES |
CVE-2022-0141HIGH The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary for | Apr 12, 2022 | 8.1 | 21 | NO | NO |
CVE-2023-47518MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Matthew Muro Restrict Categories plugin <= 2.6.4 versions. | Nov 14, 2023 | 6.1 | 19 | NO | NO |
CVE-2022-1046MEDIUM The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Script | May 2, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-24514MEDIUM The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in | Oct 25, 2021 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vfbpro.
Media articles that mention a CVE ID that affects a product developed by Vfbpro — matched by CVE ID, not by vendor name.