CVE Database /
CVE-2021-24144
CVE · High
CVE-2021-24144 — Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.5.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24144
|
Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.5.6 |
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') |
High
7.8
|
< 1.2.5.6
|
1.2.5.6 |
2021-01-25 |
—
|
CVE-2021-24144
The Contact Form 7 Database Addon plugin versions prior to 1.2.5.6 allows unauthenticated attackers to inject malicious formulas into exported CSV files, which can lead to arbitrary command execution when the files are opened in applications like Microsoft Excel through DDE exploitation, or facilitate data theft through crafted link injections.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings