PT-2022-22908 · WordPress · Export/Import Users/Customers

Adel Bouaricha

·

Published

2022-11-07

·

Updated

2022-11-10

·

CVE-2022-3558

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Import and export users and customers WordPress plugin versions prior to 1.20.5
Description The issue concerns the improper escaping of data when exporting it via CSV files. This could potentially lead to security issues, although specific details about exploitation or affected devices are not provided.
Recommendations For versions prior to 1.20.5, update to version 1.20.5 or later to resolve the issue. As a temporary workaround, consider avoiding the export of user and customer data via CSV files until the update is applied.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-3558

Affected Products

Export/Import Users/Customers