CVE-2023-36527: WordPress Post to CSV by BestWebSoft plugin <= 1.4.0 - CSV Injection
Published Nov 7, 2023
·Updated
A vulnerability in bestweblayout Post to CSV by BestWebSoft post-to-csv.This issue affects Post to CSV by BestWebSoft: from n/a through <= 1.4.0.
Affected Software
1 affected component
Bestwebsoft Post To Csv Wordpress<=1.4.0
Remediation
Information
Update to 1.4.1 or a higher version.
Event History
Nov 7, 2023
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-36527?
CVE-2023-36527 is a vulnerability in the BestWebSoft Post to CSV plugin for WordPress that allows for CSV Injection.
2
What is the severity of CVE-2023-36527?
The severity of CVE-2023-36527 is high, with a CVSS score of 8.8.
3
How does CVE-2023-36527 affect BestWebSoft Post to CSV?
CVE-2023-36527 affects BestWebSoft Post to CSV versions up to and including 1.4.0.
4
How can I fix CVE-2023-36527?
To fix CVE-2023-36527, it is recommended to update to the latest version of BestWebSoft Post to CSV plugin.
5
Where can I find more information about CVE-2023-36527?
More information about CVE-2023-36527 can be found at the following link: [CVE-2023-36527](https://patchstack.com/database/vulnerability/post-to-csv/wordpress-post-to-csv-by-bestwebsoft-plugin-1-4-0-csv-injection?_s_id=cve)