WordPress Email Subscribers & Newsletters Plugin <= 5.5.2 is vulnerable to CSV Injection
CVE-2022-45810
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 November 2023
What is CVE-2022-45810?
An improper neutralization of formula elements in CSV files has been identified in Icegram Express, used for email marketing within WordPress and WooCommerce. This vulnerability can be exploited by an attacker through crafted CSV files to execute arbitrary formulas when these files are opened by users, posing a risk of unauthorized commands and potential data exposure. Users should ensure that they are running the latest versions and apply necessary precautions against CSV file manipulations.
Affected Version(s)
Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce <= 5.5.2