CVE-2022-4368 Information

Description

The WP CSV WordPress plugin through 1.8.0.0 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV and doe snot have CSRF checks in place as well leading to a Reflected Cross-Site Scripting.

Reference

https://wpscan.com/vulnerability/fa7e2b64-ca48-4b76-a2c2-f5e31e42eab7

Share on: