WordPress Plugin Vulnerabilities

Newsletter < 6.5.4 - CSV Injection

Description

A CSV Injection vulnerability was discovered in Wordpress Newsletter plugin. It allows a user with low level privileges or no privileges to inject a command in subscription form that will be included in the exported CSV file, leading to possible code execution.

Affects Plugins

Fixed in 6.5.4

References

Classification

Type
INJECTION
OWASP top 10
CVSS

Miscellaneous

Original Researcher
Vishnupriya Ilango of Fortinet's FortiGuard Labs
Verified
No

Timeline

Publicly Published
2020-03-16 (about 6 years ago)
Added
2020-03-17 (about 6 years ago)
Last Updated
2020-08-12 (about 5 years ago)

Other