CVE-2022-46802: WordPress Product Reviews Import Export for WooCommerce plugin <= 1.4.8 - Unauth. CSV Injection vulnerability
Published Nov 7, 2023
·Updated
A vulnerability in WebToffee Product Reviews Import Export for WooCommerce product-reviews-import-export-for-woocommerce.This issue affects Product Reviews Import Export for WooCommerce: from n/a through <= 1.4.8.
Affected Software
1 affected component
WebToffee Product Reviews Import Export For Woocommerce Wordpress<=1.4.8
Remediation
Information
Update to 1.4.9 or a higher version.
Event History
Nov 7, 2023
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-46802.
2
What is the title of this vulnerability?
The title of this vulnerability is 'WordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injection.'
3
What is the affected software?
The affected software is WebToffee Product Reviews Import Export for WooCommerce version 1.4.8 and below.
4
What is the severity of this vulnerability?
The severity of this vulnerability is critical with a CVSS score of 9.8.
5
How can I fix this vulnerability?
To fix this vulnerability, update WebToffee Product Reviews Import Export for WooCommerce plugin to the latest version.