GeoDirectory – WordPress Business Directory Plugin, or Classified Directory, 5eca4bfed9c9d992a7e65a3ccf60f59a4ab4039b
- CVE, Research URL
- Home page URL
- Published on
- Dec 20, 2022
- Research Description
- GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] < 2.2.20 GeoDirectory <= 2.2.19 - CSV Injection The GeoDirectory plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.19. This allows administrator-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
- Affected versions
-
max 2.2.20.
- Status
-
vulnerable