WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Visual Form Builder

Build beautiful, fully functional contact forms in only a few minutes without writing PHP, CSS, or HTML.

8Reported vulnerabilities
9.8Highest CVSS score
3.1Latest version
20,000+Active installs

What to do now

Update Visual Form Builder to 3.0.7 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: May 27, 2022 / Tested up to WordPress: 6.0.14 / View on wordpress.org

This plugin has not been updated in over two years. New vulnerabilities may never be fixed. Consider an alternative.

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-0142 Critical 9.8 2.9% Before 3.0.6 3.0.6 April 12, 2022
CVE-2022-0140 Medium 5.3 3.8% Before 3.0.6 3.0.6 April 12, 2022
CVE-2022-1046 Medium 4.8 0.6% Before 3.0.7 3.0.7 May 2, 2022
CVE-2021-24514 Medium 4.8 0.6% Before 3.0.4 3.0.4 October 25, 2021
WF-373e9a7c-cdc3-43cb-9c8f-2be25f514b61 High 8.8 Before 2.8.3 2.8.3 May 15, 2015
CVE-2022-0141 High 8.1 0.5% Before 3.0.6 3.0.6 April 12, 2022
WF-79289ad7-f289-4472-973d-d0ec2996c5c5 High 7.2 Before 2.8.3 2.8.3 May 15, 2015
WF-16e2c051-6ec6-4b09-8802-adb537fa9af0 Medium 6.1 Before 2.8.3 2.8.3 May 15, 2015

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.