The plugin does not validate data when outputting it back in a CSV file, which could lead to CSV injection.
- Place a WooCommerce order using "=5+5" as first_name. - Export the data as CSV. - Open the CSV with a spreadsheet application (Excel, Libre Office). - The CSV formula gets executed.
Francesco Carlucci
Francesco Carlucci
Yes
2022-11-09 (about 4 months ago)
2022-11-03 (about 4 months ago)
2022-11-09 (about 4 months ago)