Description
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
References
https://wpscan.com/vulnerability/0eae5189-81af-4344-9e96-dd1f4e223d41
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2022-11-14T15:15:52.170
2 years agoLast modified
2022-11-16T19:11:47.043
2 years ago