CVE Vulnerabilities

CVE-2022-3603

Published: Nov 28, 2022 | Modified: Apr 25, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CSV file, which could lead to CSV injection.

Affected Software

Name Vendor Start Version End Version
Export_customers_list_csv_for_woocommerce Piwebsolution * 2.0.69 (excluding)

References