MSTW CSV EXPORTER
MSTW CSV EXPORTER has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for MSTW CSV EXPORTER has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Jin Yub. MSTW CSV EXPORTER is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2025-62944MSTW CSV EXPORTER <= 1.4 - Missing Authorization
Read the full analysisVulnerability Records

MSTW CSV EXPORTER
Author
Mark O'Donnell
The MSTW CSV Exporter plugin exports all data types from the MSTW Game Schedules, MSTW Game Locations, and MSTW Schedules & Scoreboards plugins to CSV format files for import into the MSTW Schedules & Scoreboards v4.0 plugin, and the MSTW Team Roster (v3.2.1) plugin for import into the MSTW Team Rosters (v4.0) plugin. This data export/import is necessary to allow the migration of plugin data across sites. The plugin also exports MSTW Schedules & Scoreboards v4.0 and MSTW Team Rosters v4.0 data. Version 1.2 adds the ability to export the MSTW Team Rosters (v3.2.1) data structures – Players and Teams – for import to MSTW Team Rosters v4.0. It allows player photos to be moved from site to site automagically in the import/export process (or not if you are upgrading Team Rosters on one site). See the Team Rosters CSV Import man page for more information. Helpful Links When all else fails try reading the user’s manual at shoalsummitsolutions.com -»
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C