WP-CRM – Customer Relations Management for WordPress [wp-crm] <= 1.2.1 (unfixed + closed)
unknown
[en] The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
- Affected:
- up to 1.2.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 13, 2022
CVE-2022-1202 on NVD →
WP-CRM – Customer Relations Management for WordPress <= 1.2.1 - CSV injection
high
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
- CVSS:
- 7.2
- Affected:
- up to 1.2.1
- Fix:
- No patched version reported
- Disclosed:
- May 18, 2022
CVE-2022-1202 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database