PDQ CSV [pdq-csv] < 2.0.0
unknown[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ransom Christofferson PDQ CSV plugin <= 1.0.0 versions.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 8, 2023
plugin
2 known security issues reported for the Pdq Csv WordPress plugin. Most recent disclosed Aug 8, 2023.
Running Pdq Csv on your site? Check whether your installed version is affected.
Scan your site free[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ransom Christofferson PDQ CSV plugin <= 1.0.0 versions.
The PDQ CSV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free