cleantalk
Vulnerabilities and Security Researches

Jetpack – WP Security, Backup, Speed, & Growth, 7b4bc72eb58f6eb409ec7f6222a169e5917d3585

Published on
Apr 26, 2017
Research Description
Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth [jetpack] < 4.2 Jetpack – WP Security, Backup, Speed, & Growth < 4.2 - CSV Injection The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.2. This allows unauthenticated attackers to embed untrusted input into data via contact forms that will be injected into exported CSV files. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Affected versions
max 4.2.
Status
vulnerable