CVE-2021-24144

Publication date

2021-03-18 14:57:50

Family

WPScan

State

PUBLISHED

Description

Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.