CVE-2018-10504
Published Apr 27, 2018The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
Vendor/product archive
2 CVEs tagged to web-dorado / form_maker — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.