CVE-2022-46804 MEDIUM

CVE-2022-46804: WordPress Export Users Data Distinct Plugin <= 1.3 is vulnerable to CSV Injection

Vendor Narola Infotech Solutions Llp
Product Export Users Data Distinct
Weakness CWE-1236
Published November 7, 2023
Last update April 28, 2026

CVSS base score

5.8/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N

What the vulnerability does

01Description

Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.

Explanation of Vulnerability in Simple Terms

02Summary

Export Users Data Distinct versions up to 1.3 contain an integrity vulnerability that allows an authenticated user with low privileges to modify data through a network request. The attack requires user interaction and high attack complexity. The scope is changed, meaning the impact may extend beyond the vulnerable component itself.

What an attacker can do

03Attacker Capabilities

Modify data on the site by tricking a user into visiting a malicious link or page.

Potential impact on your site

04Site Impact

An authenticated user can alter site data if socially engineered to visit an attacker's page.

Conditions required to exploit

05Prerequisites

Attacker needs a low-privilege account; victim must click a link or visit a page the attacker controls.

Key dates

06Disclosure timeline

November 7, 2023 CVE published
April 28, 2026 Record updated