CSV Injection Vulnerability in Hustle Plugin for WordPress
CVE-2019-11872
8.8HIGH
What is CVE-2019-11872?
The Hustle plugin version 6.0.7 for WordPress is susceptible to CSV Injection, allowing attackers to inject harmful code into pop-up windows. This vulnerability arises because the plugin fails to properly sanitize user input, enabling the insertion of arbitrary text. If exploited, an attacker could leverage this flaw to execute malicious code on the administrator's machine through Excel functions, posing a significant risk to the security of the WordPress site.