vendor:
WordPress Export Users to CSV
by:
Javier Olmedo
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: WordPress Export Users to CSV
Affected Version From: 1.1.1
Affected Version To: Before
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:a:wordpress:export_users_to_csv:1.1.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: PHP
2018
WordPress Plugin Export Users to CSV 1.1.1 – CSV Injection
WordPress Export Users to CSV plugin version 1.1.1. and before are affected by Remote Code Execution through the CSV injection vulnerability. This allows an application user to inject commands as part of the fields of his profile and these commands are executed when a user with greater privilege exports the data in CSV and opens that file on his machine.
Mitigation:
Update to the latest version of the plugin.