Statify – Extended Evaluation <= 2.6.3 - Authenticated (Admin+) CSV Injection

2023-09-18 00:00
Anonymous

Strategic Overview

Status
Patched in 2.6.4
Affected Version
< 2.6.4
CVSS
5.5Medium
Weakness type
CWE-1236 · Improper Neutralization of Formula Elements in a CSV File
CVE
CVE pending
View all Statify – Extended Evaluation vulnerabilities

At a glance

This record tracks a medium-severity Improper Neutralization of Formula Elements in a CSV File vulnerability in the Statify WordPress plugin, affecting versions < 2.6.4. It carries a CVSS score of 5.5 (reachable over the network; low attack complexity). Exploitation requires an authenticated account at Admin level or above. The issue is fixed in version 2.6.4; sites on affected versions should update now. Disclosed September 2023.

Vulnerability Overview

The Statify – Extended Evaluation plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.6.3 via the eefstatifyTableToCsv() function. This allows authenticated attackers, with administrative-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.

CWE-1236: Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Remediation

Update to version 2.6.4, or a newer patched version

How does WordSec protect against this?

An attacker needs Admin access first, so the firewall sees the attempt as traffic from a logged-in account: WordSec's web application firewall inspects request payloads before WordPress loads them. None of that substitutes for the fix: Statify 2.6.4 closes this, and updating the plugin is the step that ends it.

  • Firewall
  • Alerts

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C