Vulnerability Details CVE-2022-1202
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.1%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2022-1202
-
cpe:2.3:a:usabilitydynamics:wp-crm:-
-
cpe:2.3:a:usabilitydynamics:wp-crm:1.2.1