CVE Database /
CVE-2022-3634
CVE · Critical
CVE-2022-3634 — Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3634
|
Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.5 |
Improper Neutralization of Formula Elements in a CSV File |
Critical
9.8
|
< 1.2.6.5
|
1.2.6.5 |
2022-10-27 |
—
|
CVE-2022-3634
The Contact Form 7 Database Addon plugin contains a CSV injection vulnerability affecting versions 1.2.6.3 and earlier. An attacker can inject malicious code into CSV files that are generated and exported by the plugin, leading to potential code execution when a user downloads and opens the file in a spreadsheet application on a susceptible system. The vulnerability was resolved in version 1.2.6.5.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings