CVE-2022-44738 MEDIUM

CVE-2022-44738: WordPress Posts and Users Stats Plugin <= 1.1.3 is vulnerable to CSV Injection

Vendor Patrick Robrecht
Product Posts and Users Stats
Weakness CWE-1236
Published November 7, 2023
Last update April 28, 2026

CVSS base score

5.8/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N

What the vulnerability does

01Description

Improper Neutralization of Formula Elements in a CSV File vulnerability in Patrick Robrecht Posts and Users Stats.This issue affects Posts and Users Stats: from n/a through 1.1.3.

Explanation of Vulnerability in Simple Terms

02Summary

Posts and Users Stats through version 1.1.3 contains an integrity vulnerability requiring low-level authentication and user interaction. An attacker with low privileges can modify data by tricking a user into visiting a malicious link. The scope is changed, meaning the impact extends beyond the vulnerable component itself.

What an attacker can do

03Attacker Capabilities

Modify site data by tricking an authenticated user into clicking a malicious link.

Potential impact on your site

04Site Impact

Site data can be altered without authorization if a user is socially engineered.

Conditions required to exploit

05Prerequisites

Low-level user account and victim must click attacker-supplied link.

Key dates

06Disclosure timeline

November 7, 2023 CVE published
April 28, 2026 Record updated