Wordpress Alert: Spreadsheet formula injection in exported CSV files
A form or report export begins a cell with formula syntax. Opening the CSV in spreadsheet software may execute a formula.
What it looks like
A form or report export begins a cell with formula syntax.
Why it matters
Opening the CSV in spreadsheet software may execute a formula.
What to check
Review export escaping for untrusted cell values.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP CSV injection reference.
- Categories: WordPress
- Tags: #WordPress Security, #Injection