vendor:
Comments Import & Export Plugin
by:
Bhushan B. Patil
7.8
CVSS
HIGH
Remote Command Execution
94
CWE
Product Name: Comments Import & Export Plugin
Affected Version From: 2.0.4 and before
Affected Version To: 2.0.4 and before
Patch Exists: YES
Related CWE: CVE-2018-11526
CPE: 2.0.4 and before
Metasploit:
N/A
Platforms Tested: WiN7_x64
2018
WordPress Plugin Comments Import & Export < 2.0.4 - CSV Injection
WordPress Comments Import & Export plugin version 2.0.4 and before are affected by the vulnerability Remote Command Execution using CSV Injection. This allows a public user to inject commands as a part of form fields and when a user with higher privilege exports the form data in CSV opens the file on their machine, the command is executed.
Mitigation:
Ensure that the application is updated to the latest version of the plugin.