Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Adel Bouaricha

#15105of 53,633
17.8Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2022-23316
9.8
2022-11-21
WordPress · Contact Form 7 Database Addon · CVE-2022-3634
**Name of the Vulnerable Software and Affected Versions** Contact Form 7 Database Addon WordPress plugin versions prior to 1.2.6.5 **Description** The issue concerns the Contact Form 7 Database Addon WordPress plugin, which does not validate data when outputting it back in a CSV file. This could lead to CSV injection. **Recommendations** For versions prior to 1.2.6.5, update to version 1.2.6.5 or later to resolve the issue.
PT-2022-22908
8.0
2022-11-07
WordPress · Export/Import Users/Customers · CVE-2022-3558
**Name of the Vulnerable Software and Affected Versions** Import and export users and customers WordPress plugin versions prior to 1.20.5 **Description** The issue concerns the improper escaping of data when exporting it via CSV files. This could potentially lead to security issues, although specific details about exploitation or affected devices are not provided. **Recommendations** For versions prior to 1.20.5, update to version 1.20.5 or later to resolve the issue. As a temporary workaround, consider avoiding the export of user and customer data via CSV files until the update is applied.