CVE-2022-3600: Easy Digital Downloads < 3.1.0.2 - Unauthenticated CSV Injection
Published Nov 21, 2022
·Updated
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.
Affected Software
2 affected components
Sandhillsdev Easy Digital Downloads Wordpress<3.1.0.2
Awesomemotive Easy Digital Downloads Wordpress<3.1.0.2
Event History
Nov 21, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Easy Digital Downloads WordPress plugin issue?
The vulnerability ID for this Easy Digital Downloads WordPress plugin issue is CVE-2022-3600.
2
What is the severity level of CVE-2022-3600?
The severity level of CVE-2022-3600 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is the Easy Digital Downloads WordPress plugin version up to and excluding 3.1.0.2.
4
What is the risk of the vulnerability?
The risk of the vulnerability is CSV injection, which can occur when the plugin outputs data in a CSV file without proper validation.
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update the Easy Digital Downloads WordPress plugin to version 3.1.0.2 or later.