CSV Injection Vulnerability in WS Form LITE Plugin for WordPress
CVE-2023-5424
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 June 2024
What is CVE-2023-5424?
The WS Form LITE plugin for WordPress is susceptible to a CSV Injection vulnerability, impacting all versions up to and including 1.9.217. This flaw permits unauthenticated attackers to incorporate untrusted input into exported CSV files. When these CSV files are downloaded and opened on a system configured in a vulnerable manner, they may execute unintended code, posing significant security risks. Users of the WS Form LITE plugin are advised to update to the latest version and review security practices to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WS Form LITE β Drag & Drop Contact Form Builder for WordPress * <= 1.9.217
WS Form Pro * <= 1.9.217
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved