6.8
CVSSv2

CVE-2018-11526

Published: 19/06/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

Vulnerable Product Search on Vulmon Subscribe to Product

webtoffee wordpress comments import and export

Exploits

# Exploit Title: Wordpress Plugin Comments Import & Export < 204 - CSV Injection # Google Dork: N/A # Date: 2018-06-24 # Exploit Author: Bhushan B Patil # Software Link: wordpressorg/plugins/comments-import-export-woocommerce/ # Affected Version: 204 and before # Category: Plugins and Extensions # Tested on: WiN7_x64 # CVE: CVE ...
WordPress Comments Import and Export plugin versions prior to 204 suffer from a CSV injection vulnerability ...