CVE-2019-11872: High severity hustle vulnerability
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11872?
CVE-2019-11872 is a vulnerability in The Hustle (aka wordpress-popup) plugin for WordPress that allows for CSV Injection, enabling an attacker to inject malicious code into a pop-up window.
How severe is CVE-2019-11872?
CVE-2019-11872 has a severity of 8.8 (high).
How can the CVE-2019-11872 vulnerability be exploited?
The CVE-2019-11872 vulnerability can be exploited by injecting malicious code into a pop-up window, granting an attacker the ability to execute malicious code on the administrator's computer through Excel functions.
Is there a fix available for CVE-2019-11872?
Yes, a fix for CVE-2019-11872 is available in version 6.0.8.1 of The Hustle (aka wordpress-popup) plugin for WordPress.
Where can I find more information about CVE-2019-11872?
More information about CVE-2019-11872 can be found in the following references: <ul><li><a href='https://blog.reddy.io/2019/05/24/reddy-solutions-found-a-csv-injection-vulnerability-in-hustle-wordpress-plugin/'>https://blog.reddy.io/2019/05/24/reddy-solutions-found-a-csv-injection-vulnerability-in-hustle-wordpress-plugin/</a></li><li><a href='https://blog.reddy.io/category/cybersecurity/'>https://blog.reddy.io/category/cybersecurity/</a></li><li><a href='https://wordpress.org/plugins/wordpress-popup/#developers'>https://wordpress.org/plugins/wordpress-popup/#developers</a></li></ul>