The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wp_csv_exporter | Wp_csv_exporter_project | * | 1.3.7 (excluding) |