vendor:
Advanced Order Export For WooCommerce
by:
Bhushan B. Patil
7.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Advanced Order Export For WooCommerce
Affected Version From: 1.5.4 and before
Affected Version To: 1.5.4
Patch Exists: YES
Related CWE: CVE-2018-11525
CPE: 2.3:a:wordpress:advanced_order_export_for_woocommerce
Metasploit:
N/A
Platforms Tested: WiN7_x64
2018
WordPress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection
Advanced Order Export For WooCommerce plugin version 1.5.4 and before are affected by the vulnerability Remote Command Execution using CSV Injection. This allows a public user to inject commands as a part of form fields and when a user with higher privilege exports the form data in CSV opens the file on their machine, the command is executed.
Mitigation:
Upgrade to version 1.5.4 or later