WordPress Plugin Vulnerabilities

CSV to SortTable <= 4.2 - Contributor+ LFI

Description

The plugin does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
LFI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Ivan Cese
Submitter
Ivan Cese
Verified
Yes

Timeline

Publicly Published
2025-11-18 (about 1 month ago)
Added
2025-11-18 (about 1 month ago)
Last Updated
2025-11-18 (about 1 month ago)

Other