First published: Mon Nov 14 2022(Updated: )
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPForms Contact Form | <1.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3574 is critical with a CVSS score of 9.8.
CVE-2022-3574 affects WPForms Pro WordPress plugin version up to exclusive 1.7.7.
The vulnerability in WPForms Pro WordPress plugin before 1.7.7 is the lack of form data validation when generating exported CSV, leading to CSV injection.