What the vulnerability does
01Description
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Explanation of Vulnerability in Simple Terms
02Summary
Ultimate SMS Notifications for WooCommerce version 1.4.1 contains a vulnerability that allows an authenticated user with low privileges to perform actions affecting the site's confidentiality, integrity, and availability. The attack requires user interaction and can impact components beyond the plugin itself. Site administrators should update to a patched version when available.
What an attacker can do
03Attacker Capabilities
An authenticated user can trigger actions that may leak data, modify content, or disrupt service.
Potential impact on your site
04Site Impact
Your WooCommerce site's data, content, or availability could be compromised by a low-privilege user account.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account and trick a user into clicking a malicious link or visiting a crafted page.
Key dates
06Disclosure timeline
September 6, 2022
CVE published
January 31, 2025
Record updated