CVE-2018-11526: High severity webtoffee wordpress comments import and export vulnerability
Published Jun 19, 2018
·Updated
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
Affected Software
1 affected component
WebToffee Wordpress Comments Import And Export Wordpress<=2.0.4
Event History
Jun 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11526?
The severity of CVE-2018-11526 is high.
2
How does the vulnerability CVE-2018-11526 affect WordPress Comments Import & Export plugin?
The vulnerability CVE-2018-11526 affects WordPress Comments Import & Export plugin (v2.0.4 and before).
3
What is CSV Injection?
CSV Injection is a technique that enables an attacker to execute arbitrary commands by injecting malicious data into a CSV file.
4
What is the affected version of WordPress Comments Import & Export plugin for CVE-2018-11526?
The affected version of WordPress Comments Import & Export plugin for CVE-2018-11526 is v2.0.4 and earlier.
5
How can I mitigate the vulnerability CVE-2018-11526?
To mitigate the vulnerability CVE-2018-11526, update WordPress Comments Import & Export plugin to the latest version.