CVE-2022-38061: WordPress Export Post Info plugin <= 1.2.0 - Authenticated CSV Injection vulnerability
Published Sep 23, 2022
·Updated
Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at WordPress.
Affected Software
1 affected component
Apasionados Export Post Info Wordpress<=1.2.0
Remediation
Information
Update to 1.2.1 or higher version.
Event History
Sep 23, 2022
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-38061?
The severity of CVE-2022-38061 is medium with a severity value of 5.7.
2
What is the affected software for CVE-2022-38061?
The affected software for CVE-2022-38061 is the Export Post Info plugin version 1.2.0 or below in WordPress.
3
How can I fix CVE-2022-38061?
To fix CVE-2022-38061, update the Export Post Info plugin to a version higher than 1.2.0.
4
What is CSV Injection?
CSV Injection is a type of vulnerability where specially crafted input in a CSV file can cause arbitrary commands to be executed when opened.
5
What is the CWE ID for CVE-2022-38061?
The CWE ID for CVE-2022-38061 is 1236.