WordPress Export Users Data Distinct Plugin <= 1.3 is vulnerable to CSV Injection
CVE-2022-46804

5.8MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 November 2023

What is CVE-2022-46804?

An improper neutralization vulnerability allows attackers to craft malicious CSV files that can execute arbitrary code or commands when opened in a spreadsheet application. This can lead to potential data manipulation and unauthorized access, affecting the integrity of the user data exported through the Export Users Data Distinct plugin from Narola Infotech Solutions. Users of versions n/a through 1.3 should take immediate action to mitigate risks associated with this issue.

Affected Version(s)

Export Users Data Distinct <= 1.3

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.