Output validation vulnerability in WS Form LITE – Drag & Drop Contact Form Builder for WordPress 1.9.217

The WS Form LITE plugin for WordPress has a security issue where attackers can insert harmful code into exported CSV files. This can happen in versions 1.9.217 and below, and it can lead to code execution if the file is downloaded and opened on a vulnerable computer without proper authentication.

Detected in:

WS Form LITE – Drag & Drop Contact Form Builder for WordPress fixed vulnerable versions: >= * <= 1.9.217
WS Form Pro fixed vulnerable versions: >= * <= 1.9.217

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.