The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/300ebfcd-c500-464e-b919-acfeb72593de/ | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/300ebfcd-c500-464e-b919-acfeb72593de/ | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 07:19
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://wpscan.com/vulnerability/300ebfcd-c500-464e-b919-acfeb72593de/ - Exploit, Third Party Advisory | 
24 Jan 2024, 16:58
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:crmperks:database_for_contact_form_7\,_wpforms\,_elementor_forms:*:*:*:*:*:*:*:* | |
| CWE | CWE-1236 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.8 | 
| References | () https://wpscan.com/vulnerability/300ebfcd-c500-464e-b919-acfeb72593de/ - Exploit, Third Party Advisory | |
| First Time | Crmperks database For Contact Form 7\, Wpforms\, Elementor Forms Crmperks | 
16 Jan 2024, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-01-16 16:15
Updated : 2025-06-11 17:15
NVD link : CVE-2022-3604
Mitre link : CVE-2022-3604
CVE.ORG link : CVE-2022-3604
JSON object : View
Products Affected
                crmperks
- database_for_contact_form_7\,_wpforms\,_elementor_forms
CWE
                
                    
                        
                        CWE-1236
                        
            Improper Neutralization of Formula Elements in a CSV File
