The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Wp_csv_exporter | Wp_csv_exporter_project | * | 1.3.7 (excluding) |
References