ZeroHour

CVE-2022-3574

PoC
CVSS 3.1
9.8 critical
EPSS
1%p71
Published
()
Modified
Description

The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

Vendors
wpforms
Products
wpforms pro
Ecosystems
WordPress
Weakness
CWE-1236
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.