User Blocker <= 1.5.5 - Authenticated (Admin+) CSV Injection
mediumThe User Blocker plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.5.5. This allows administrator-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable conf...
- CVSS:
- 5.9
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.6
- Disclosed:
- Nov 9, 2022