First published: Tue Jun 19 2018(Updated: )
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AlgolPlus Advanced Order Export For WooCommerce | <=1.5.4 | |
AlgolPlus Advanced Order Export For WooCommerce | <=1.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-11525.
The plugin affected by this vulnerability is Advanced Order Export For WooCommerce.
The severity of CVE-2018-11525 is high with a severity score of 7.8.
The vulnerability CSV Injection occurs in Advanced Order Export For WooCommerce due to improper handling of CSV data.
Yes, there is a fix available for CVE-2018-11525. It is recommended to update to a version of the plugin that is not vulnerable.