What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
What the vulnerability does
Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.
Explanation of Vulnerability in Simple Terms
UsersWP versions up to 1.2.3.9 contain an integrity vulnerability that allows an authenticated attacker to modify data on the site. The attack requires user interaction and high attack complexity. The vulnerability affects the scope beyond the vulnerable component itself. Update to version 1.2.65 or later to remediate.
What an attacker can do
Modify site data or content through a crafted request.
Potential impact on your site
Authenticated users could alter site content or settings without authorization if socially engineered.
Conditions required to exploit
Attacker must be logged in with low-level privileges and trick a user into clicking a malicious link.
Key dates
External resources
Related vulnerabilities