WordPress KB Support Plugin <= 1.5.84 is vulnerable to CSV Injection
CVE-2023-25983
8.8HIGH
What is CVE-2023-25983?
A vulnerability exists in the WPOmnia KB Support plugin for WordPress that could allow an attacker to exploit improper neutralization of formula elements in CSV files. This issue affects versions from n/a to 1.5.84, potentially allowing for unauthorized data manipulation and execution of arbitrary commands when a user opens a crafted CSV file. It is crucial for users of this plugin to apply necessary updates and adhere to security best practices to mitigate risks.
Affected Version(s)
KB Support <= 1.5.84