cleantalk
Vulnerabilities and Security Researches

GeoDirectory – WordPress Business Directory Plugin, or Classified Directory, 5eca4bfed9c9d992a7e65a3ccf60f59a4ab4039b

Published on
Dec 20, 2022
Research Description
GeoDirectory &#8211; WP Business Directory Plugin and Classified Listings Directory [geodirectory] < 2.2.20 GeoDirectory <= 2.2.19 - CSV Injection The GeoDirectory plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.19. This allows administrator-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Affected versions
max 2.2.20.
Status
vulnerable