WordPress Plugin Vulnerabilities

Wise Chat < 2.8.4 - CSV Injection

Description

It could allow an unauthenticated or low privileges user to inject a command in chat messages that will be included in the exported CSV file (via message backup), leading to possible code execution.

Affects Plugins

Fixed in 2.8.4

References

Classification

Type
INJECTION
OWASP top 10
CVSS

Miscellaneous

Original Researcher
Vishnupriya Ilango of Fortinet's FortiGuard Labs
Verified
No

Timeline

Publicly Published
2020-07-09 (about 5 years ago)
Added
2020-07-09 (about 5 years ago)
Last Updated
2020-07-10 (about 5 years ago)

Other