WordPress Email Subscribers & Newsletters Plugin <= 5.5.2 is vulnerable to CSV Injection
CVE-2022-45810

9.8CRITICAL

Summary

An improper neutralization of formula elements in CSV files has been identified in Icegram Express, used for email marketing within WordPress and WooCommerce. This vulnerability can be exploited by an attacker through crafted CSV files to execute arbitrary formulas when these files are opened by users, posing a risk of unauthorized commands and potential data exposure. Users should ensure that they are running the latest versions and apply necessary precautions against CSV file manipulations.

Affected Version(s)

Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce <= 5.5.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.