CVE-2023-0721: Metform Elementor Contact Form Builder <= 3.3.0 - Unauthenticated CSV Injection
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-0721?
CVE-2023-0721 is a vulnerability in the Metform Elementor Contact Form Builder plugin for WordPress that allows unauthenticated attackers to execute arbitrary code by injecting malicious CSV files.
How does CVE-2023-0721 affect the Metform Elementor Contact Form Builder plugin?
CVE-2023-0721 affects versions up to and including 3.3.0 of the Metform Elementor Contact Form Builder plugin for WordPress.
What is the severity of CVE-2023-0721?
CVE-2023-0721 has a severity rating of 7.8 (High).
How can an unauthenticated attacker exploit CVE-2023-0721?
An unauthenticated attacker can exploit CVE-2023-0721 by embedding malicious input into exported CSV files, which can lead to code execution when the files are downloaded and opened.
Is there a fix available for CVE-2023-0721?
Yes, to fix CVE-2023-0721, users should update to a version of the Metform Elementor Contact Form Builder plugin for WordPress that is higher than 3.3.0.