WPForms Pro < 1.7.7 - CSV Injection
CVE-2022-3574
9.8CRITICAL
What is CVE-2022-3574?
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
Affected Version(s)
WPForms Pro 1.7.7