WordPress Plugin Vulnerabilities
Newsletter < 6.5.4 - CSV Injection
Description
A CSV Injection vulnerability was discovered in Wordpress Newsletter plugin. It allows a user with low level privileges or no privileges to inject a command in subscription form that will be included in the exported CSV file, leading to possible code execution.
Affects Plugins
References
Classification
Type
INJECTION
OWASP top 10
CVSS
Miscellaneous
Original Researcher
Vishnupriya Ilango of Fortinet's FortiGuard Labs
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-03-16 (about 6 years ago)
Added
2020-03-17 (about 6 years ago)
Last Updated
2020-08-12 (about 5 years ago)