CVE-2018-9035
CRITICALContact Form 7 to Database Ext <2.10.32 - Code Injection
Title source: llmDescription
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.
Exploits (2)
Scores
CVSS v3
9.6
EPSS
0.0841
EPSS Percentile
92.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-1236
Status
published
Products (1)
contact-form-7-to-database-extension_project/contact-form-7-to-database-extension
< 2.10.32
Published
Apr 04, 2018
Tracked Since
Feb 18, 2026