CSV Injection Vulnerability in WS Form LITE Plugin for WordPress
CVE-2023-5424
8.8HIGH
Key Information:
- Vendor
- Westguard
- Status
- Ws Form Lite – Drag & Drop Contact Form Builder For WordPress
- Ws Form Pro
- Vendor
- CVE Published:
- 7 June 2024
Summary
The WS Form LITE plugin for WordPress is susceptible to a CSV Injection vulnerability, impacting all versions up to and including 1.9.217. This flaw permits unauthenticated attackers to incorporate untrusted input into exported CSV files. When these CSV files are downloaded and opened on a system configured in a vulnerable manner, they may execute unintended code, posing significant security risks. Users of the WS Form LITE plugin are advised to update to the latest version and review security practices to mitigate potential threats.
Affected Version(s)
WS Form LITE – Drag & Drop Contact Form Builder for WordPress * <= 1.9.217
WS Form Pro * <= 1.9.217
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Duc Manh