CVE-2022-45810: WordPress Icegram Express – Email Subscribers, Newsletters and Marketing Automation Plugin plugin <= 5.5.2 - CSV Injection
A vulnerability in Icegram Email Subscribers & Newsletters email-subscribers.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.5.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-45810?
CVE-2022-45810 is a vulnerability in the WordPress Email Subscribers & Newsletters Plugin version <= 5.5.2 that allows CSV Injection.
How severe is CVE-2022-45810?
CVE-2022-45810 has a severity rating of 9.8 (critical).
What software is affected by CVE-2022-45810?
The Icegram Express – Email Marketing, Newsletters and Automation plugin for WordPress & WooCommerce version <= 5.5.2 is affected by CVE-2022-45810.
How can I fix CVE-2022-45810?
To fix CVE-2022-45810, you should update the WordPress Email Subscribers & Newsletters Plugin to a version higher than 5.5.2.
What is CSV Injection?
CSV Injection is a vulnerability that allows an attacker to execute malicious commands when a CSV file is opened or imported by certain applications.