Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
| Software | From | Fixed in |
|---|---|---|
| ciphercoin / contact_form_7_database_addon | - | 1.2.5.6 |