WordCamp Talks < 1.0.0 Beta3 - CSV Injection
highThe WordCamp Talks plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.0.0 Beta2 via the wct_generate_csv_content() function. This allows authenticated attackers, with contributor-level permissions and above, to embed untrusted input into exported CSV files, which can result in code...
- CVSS:
- 8
- Affected:
- up to 1.0.0-beta3
- Fixed in:
- 1.0.0-beta3
- Disclosed:
- Oct 23, 2017