The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Wp_csv_exporter |
Wp_csv_exporter_project |
* |
1.3.7 (excluding) |
References