PT-2025-32633 · WordPress · Anwp Football Leagues

Published

2025-08-12

·

Updated

2025-08-12

·

CVE-2025-8767

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: AnWP Football Leagues plugin for WordPress versions up to and including 0.16.17
Description: The AnWP Football Leagues plugin for WordPress is susceptible to CSV injection through the download csv players and download csv games functions. Authenticated attackers with Administrator-level access or higher can embed untrusted input into exported CSV files. This can lead to code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Recommendations: Update the AnWP Football Leagues plugin to a version later than 0.16.17.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-8767

Affected Products

Anwp Football Leagues