Export customers list csv for WooCommerce <= 2.0.67 - CSV Injection
mediumThe Export customers list csv plugin for WooCommerce is vulnerable to CSV Injection in versions up to, and including, 2.0.67. This allows high-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerab...
- CVSS:
- 4.8
- Affected:
- up to 2.0.67
- Fixed in:
- 2.0.69
- Disclosed:
- Nov 3, 2022