Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-5527 2 Businessdirectoryplugin, Strategy11team 2 Business Directory, Business Directory Plugin 2024-11-21 7.4 High
The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.