WordPress Plugin Vulnerabilities

ProfileGrid < 5.1.8 - Subscriber+ CSV Injection

Description

The plugin does not validate data when output it back in a CSV file, which could lead to CSV injection

Affects Plugins

References

Classification

Type
CSV INJECTION
OWASP top 10
CWE

Miscellaneous

Original Researcher
Mika
Verified
No

Timeline

Publicly Published
2022-11-17 (about 3 years ago)
Added
2022-11-18 (about 3 years ago)
Last Updated
2022-11-24 (about 3 years ago)

Other