Vulnerabilities > CVE-2022-4368 - Unspecified vulnerability in Cpkwebsolutions WP CSV 1.8.0.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The WP CSV WordPress plugin through 1.8.0.0 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, and doe snot have CSRF checks in place as well, leading to a Reflected Cross-Site Scripting.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |