← back
CVE-2021-24441CWE-1236

Sign-up Sheets < 1.0.14 - Authenticated CSV Injection

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.3%
exploitation probability
1.3%top 32% of all CVEs
observed exploitation
nono source reports it
In short

The Sign-up Sheets WordPress plugin failed to properly clean user input in sheet titles before creating CSV exports, allowing attackers to inject malicious formulas into downloaded files.

Technical detail

An authenticated attacker can inject CSV formula code via the sheet title parameter, which is directly embedded into exported CSV files without sanitization. When a victim opens the malicious CSV in a spreadsheet application, the formula executes with the privileges of that user.

Summary generated and translated by AI from the official description.
The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue
Affected products
Unknown · Sign-up Sheets