Wordpress Alert: Email-header injection in contact forms
A contact form accepts newline or header syntax in email fields. Messages may gain unintended recipients or headers.
What it looks like
A contact form accepts newline or header syntax in email fields.
Why it matters
Messages may gain unintended recipients or headers.
What to check
Validate email fields and keep user input out of raw mail headers.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP injection prevention, WordPress input sanitizing.
- Categories: WordPress
- Tags: #WordPress Security, #Injection