Simple CSV Table <= 1.0.1 - Directory Traversal to Authenticated (Contributor+) Arbitrary File Read
mediumThe Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.1 via the `href` parameter in the `[csv]` shortcode. This is due to insufficient path validation before concatenating user-supplied input to a base directory path. This makes it possible for authenti...
- CVSS:
- 6.5
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.2
- Disclosed:
- Dec 11, 2025