Statify – Extended Evaluation <= 2.6.3 - Authenticated (Admin+) CSV Injection
Strategic Overview
- Status
- Patched in 2.6.4
- Affected Plugin
- Statify – Extended Evaluation
- Affected Version
< 2.6.4- CVSS
- 5.5Medium
- Weakness type
- CWE-1236 · Improper Neutralization of Formula Elements in a CSV File
- CVE
CVE pending
At a glance
This record tracks a medium-severity Improper Neutralization of Formula Elements in a CSV File vulnerability in the Statify WordPress plugin, affecting versions < 2.6.4. It carries a CVSS score of 5.5 (reachable over the network; low attack complexity). Exploitation requires an authenticated account at Admin level or above. The issue is fixed in version 2.6.4; sites on affected versions should update now. Disclosed September 2023.
Vulnerability Overview
The Statify – Extended Evaluation plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.6.3 via the eefstatifyTableToCsv() function. This allows authenticated attackers, with administrative-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.
CWE-1236: Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Remediation
Update to version 2.6.4, or a newer patched version
How does WordSec protect against this?
An attacker needs Admin access first, so the firewall sees the attempt as traffic from a logged-in account: WordSec's web application firewall inspects request payloads before WordPress loads them. None of that substitutes for the fix: Statify 2.6.4 closes this, and updating the plugin is the step that ends it.
- Firewall
- Alerts
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C