The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HBestwebsoft Post To Csv
APPBestwebsoft≤ 1.4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-36527MEDIUM4.7same product
Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebS...
CVE-2017-2171MEDIUM6.1same product
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Conta...
CVE-2015-9335CRITICAL9.8PL ✓same vendor
SQL injection w pluginie Limit Attempts dla WordPress (obsługa adresu IP)
CVE-2015-9325CRITICAL9.8PL ✓same vendor
SQL injection w pluginie Visitors Online dla WordPress
CVE-2024-13908HIGH7.2same vendor
The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ...