CVE-2022-3574
published 2022-11-14CVE-2022-3574: The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
PriorityP342critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.41%
71.5th percentile
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1 | 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1 |
| wpforms | wpforms_pro | < 1.7.7 | 1.7.7 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
imagemagick vulnerabilities
osv·2022-11-24·CVSS 5.5
CVE-2021-20224 imagemagick vulnerabilities
imagemagick vulnerabilities
USN-5736-1 fixed vulnerabilities in ImageMagick. This update provides the
corresponding updates for Ubuntu 20.04 ESM and Ubuntu 22.04 ESM. One of the
issues, CVE-2021-20224, only affected Ubuntu 20.04 ESM, while
CVE-2021-20245, CVE-2021-3574, CVE-2021-4219 and CVE-2022-1114 only
affected Ubuntu 22.04 ESM.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
val
GHSA
GHSA-6mxj-jjjj-8mpv: The WPForms Pro WordPress plugin before 1
ghsa_unreviewed·2022-11-14
CVE-2022-3574 [CRITICAL] CWE-1236 GHSA-6mxj-jjjj-8mpv: The WPForms Pro WordPress plugin before 1
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-14
Published