CVE · High

CVE-2021-24144 — Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.5.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24144 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.5.6 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') High 7.8 < 1.2.5.6 1.2.5.6 2021-01-25

CVE-2021-24144

The Contact Form 7 Database Addon plugin versions prior to 1.2.5.6 allows unauthenticated attackers to inject malicious formulas into exported CSV files, which can lead to arbitrary command execution when the files are opened in applications like Microsoft Excel through DDE exploitation, or facilitate data theft through crafted link injections.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.