PT-2022-23098 · WordPress · Easy Digital Downloads

·

CVE-2022-3600

·

Published

2022-11-21

·

Updated

2022-11-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easy Digital Downloads WordPress plugin versions prior to 3.1.0.2
Description The issue concerns the lack of data validation when outputting to a CSV file, potentially leading to CSV injection. This could allow malicious data to be injected into the CSV file, posing a risk to users who open or import the file.
Recommendations For versions prior to 3.1.0.2, update to version 3.1.0.2 or later to resolve the issue. As a temporary workaround, consider avoiding the use of CSV exports from the plugin until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-3600

Affected Products

Easy Digital Downloads