CSV Injection Vulnerability in WS Form LITE Plugin for WordPress
CVE-2023-5424

8.8HIGH

Key Information:

Vendor
Westguard
Status
Ws Form Lite – Drag & Drop Contact Form Builder For WordPress
Ws Form Pro
Vendor
CVE Published:
7 June 2024

Summary

The WS Form LITE plugin for WordPress is susceptible to a CSV Injection vulnerability, impacting all versions up to and including 1.9.217. This flaw permits unauthenticated attackers to incorporate untrusted input into exported CSV files. When these CSV files are downloaded and opened on a system configured in a vulnerable manner, they may execute unintended code, posing significant security risks. Users of the WS Form LITE plugin are advised to update to the latest version and review security practices to mitigate potential threats.

Affected Version(s)

WS Form LITE – Drag & Drop Contact Form Builder for WordPress * <= 1.9.217

WS Form Pro * <= 1.9.217

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Duc Manh
.