What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in Nakashima Masahiro WP CSV Exporter.This issue affects WP CSV Exporter: from n/a through 2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
What the vulnerability does
Improper Neutralization of Formula Elements in a CSV File vulnerability in Nakashima Masahiro WP CSV Exporter.This issue affects WP CSV Exporter: from n/a through 2.0.
Explanation of Vulnerability in Simple Terms
WP CSV Exporter versions up to 2.0 contain an integrity vulnerability that allows an authenticated user with low privileges to modify data through a network-based attack. The vulnerability requires user interaction and affects the scope beyond the vulnerable component. No confidentiality or availability impact occurs.
What an attacker can do
Modify site data or content through a network request.
Potential impact on your site
Authenticated users can alter exported CSV data or site content without authorization.
Conditions required to exploit
Attacker must be logged in with low-level user account; victim must click a malicious link or visit a crafted page.
Key dates
External resources
Related vulnerabilities