First published: Tue Jan 16 2024(Updated: )
The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Crmperks Database for Contact Form 7, WPForms, Elementor Forms | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3604 has a medium severity rating due to potential CSV injection risks.
To fix CVE-2022-3604, update the Contact Form Entries WordPress plugin to version 1.3.0 or later.
CVE-2022-3604 affects the Contact Form Entries WordPress plugin before version 1.3.0.
CVE-2022-3604 is classified as a CSV injection vulnerability.
Yes, if exploited, CVE-2022-3604 could allow attackers to inject malicious content into CSV files, potentially leading to data breaches.