Export Users Data CSV <= 2.1 - Authenticated (Subscriber+) CSV Injection
mediumThe Export Users Data CSV plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.1. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable...
- CVSS:
- 6
- Affected:
- up to 2.1
- Fixed in:
- 2.2
- Disclosed:
- Nov 30, 2022