VYPR
Unrated severityNVD Advisory· Published Jul 17, 2022· Updated Aug 3, 2024

Import CSV Files <= 1.0 - Reflected Cross-Site Scripting

CVE-2022-2146

Description

The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.