CSV Injection Vulnerability in TablePress Plugin for WordPress
CVE-2019-20180
6.8MEDIUM
What is CVE-2019-20180?
The TablePress plugin version 1.9.2 for WordPress is susceptible to a CSV injection attack that may allow malicious users with Editor privileges to execute code within CSV files. While the vendor contends that the risk is attributed to the application used to open the CSV file rather than the plugin itself, it is critical for users to be aware of this vulnerability. Users are advised to exercise caution and to implement best practices for secure file handling to mitigate potential risks.