CVE · Critical

CVE-2022-3634 — Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3634 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.5 Improper Neutralization of Formula Elements in a CSV File Critical 9.8 < 1.2.6.5 1.2.6.5 2022-10-27

CVE-2022-3634

The Contact Form 7 Database Addon plugin contains a CSV injection vulnerability affecting versions 1.2.6.3 and earlier. An attacker can inject malicious code into CSV files that are generated and exported by the plugin, leading to potential code execution when a user downloads and opens the file in a spreadsheet application on a susceptible system. The vulnerability was resolved in version 1.2.6.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.