CVE-2022-46809: WordPress ReviewX plugin <= 1.6.7 - CSV Injection
Published Nov 7, 2023
·Updated
A vulnerability in ReviewX ReviewX reviewx.This issue affects ReviewX: from n/a through <= 1.6.7.
Affected Software
1 affected component
WPDeveloper Reviewx Wordpress<=1.6.7
Remediation
Information
Update to 1.6.8 or a higher version.
Event History
Nov 7, 2023
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-46809.
2
What is the severity of CVE-2022-46809?
The severity of CVE-2022-46809 is critical with a CVSS score of 9.8.
3
What is the affected software for CVE-2022-46809?
The affected software for CVE-2022-46809 is WPDeveloper ReviewX Plugin version up to and including 1.6.7.
4
What is CSV Injection?
CSV Injection is a vulnerability that allows an attacker to execute arbitrary commands or script code by injecting malicious content into a CSV file.
5
Is there a patch or fix available for CVE-2022-46809?
Yes, a patch for CVE-2022-46809 is available. Please refer to the following link for more information: [Patch for CVE-2022-46809](https://patchstack.com/database/vulnerability/reviewx/wordpress-reviewx-plugin-1-6-6-csv-injection?_s_id=cve)