Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection
CVE-2022-3558
8HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 7 November 2022
Summary
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
Affected Version(s)
Import and export users and customers 1.20.5
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adel Bouaricha