Input validation vulnerability in Contact Form Builder by vcita 4.9.1

The Contact Form Builder by vcita plugin for WordPress is not secure in versions up to and including 4.9.1. This means that someone who is not supposed to be able to make changes to the plugin could do so if they were able to get a site administrator to click on a link or do something else. This is possible because the plugin does not have the proper protection in place to stop this kind of attack.

Detected in:

Contact Form Builder by vcita fixed vulnerable versions: >= * <= 4.10.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.