Arbitrary Formula Injection Vulnerability in Contact Form 7 Database Addon Plugin

Arbitrary Formula Injection Vulnerability in Contact Form 7 Database Addon Plugin

CVE-2021-24144 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.

Learn more about our Contact.