Simple User Import Export <= 1.1.7 - Authenticated (Admin+) CSV Injection
mediumThe Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can...
- CVSS:
- 6.6
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.8
- Disclosed:
- Nov 17, 2025