WooCommerce - Store Exporter <= 2.3.1 - CSV Injection

2020-01-09 00:00
Vishnupriya Ilango

Vulnerability Overview

The WooCommerce - Store Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.3.1 via the Quick Export' functionality. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Technical Analysis

REMEDIATION: Update to version 2.4, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C