PT-2022-23127 · WordPress+1 · Export Guest Customer List Wordpress Plugin+2

Francesco Carlucci

·

Published

2022-11-28

·

Updated

2025-02-20

·

CVE-2022-3603

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin versions prior to 2.0.69
Description The issue concerns a lack of data validation when outputting data back into a CSV file, potentially leading to CSV injection.
Recommendations For versions prior to 2.0.69, update to version 2.0.69 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2022-3603

Affected Products

Export Customers List Csv For Woocommerce
Wordpress Users Csv
Export Guest Customer List Wordpress Plugin