PT-2022-22908 · WordPress · Export/Import Users/Customers
Adel Bouaricha
·
Published
2022-11-07
·
Updated
2022-11-10
·
CVE-2022-3558
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Import and export users and customers WordPress plugin versions prior to 1.20.5
Description
The issue concerns the improper escaping of data when exporting it via CSV files. This could potentially lead to security issues, although specific details about exploitation or affected devices are not provided.
Recommendations
For versions prior to 1.20.5, update to version 1.20.5 or later to resolve the issue. As a temporary workaround, consider avoiding the export of user and customer data via CSV files until the update is applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Export/Import Users/Customers