vendor:
Users & Customers Import Export for WP & WooCommerce
by:
Javier Olmedo
8.8
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Users & Customers Import Export for WP & WooCommerce
Affected Version From: 1.3.1 and before
Affected Version To: 1.3.1 and before
Patch Exists: YES
Related CWE: 2019-15092
CPE: 2.3:a:webtoffee:users_customers_import_export_for_wp_woocommerce:1.3.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win10x64
2018
WordPress Plugin Import Export WordPress Users <= 1.3.1 - CSV Injection
Wordpress Plugin Import Export WordPress Users version 1.3.1. and before are affected by Remote Code Execution through the CSV injection vulnerability. This allows any application user to inject commands as part of the fields of his profile and these commands are executed when a user with greater privilege exports the data in CSV and opens that file on his machine. The function do_export() from WF_CustomerImpExpCsv_Exporter class does not check if fields beggings with (=, +, -, @) characters so the fields name, surname, alias or display_name are vulnerable to CSV Injection.
Mitigation:
Update to 1.3.2 version