WordPress Email Subscribers & Newsletters Plugin <= 5.5.2 is vulnerable to CSV Injection
CVE-2022-45810
9.8CRITICAL
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 7 November 2023
Summary
An improper neutralization of formula elements in CSV files has been identified in Icegram Express, used for email marketing within WordPress and WooCommerce. This vulnerability can be exploited by an attacker through crafted CSV files to execute arbitrary formulas when these files are opened by users, posing a risk of unauthorized commands and potential data exposure. Users should ensure that they are running the latest versions and apply necessary precautions against CSV file manipulations.
Affected Version(s)
Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce <= 5.5.2
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)