CVE-2019-20180
The TablePress plugin for WordPress through version 1.14 contains a CSV injection vulnerability in the tablepress[data] parameter that allows authenticated users with author-level permissions or higher to inject malicious code into exported CSV files, potentially enabling code execution when those files are opened in a vulnerable environment on a local system. Although the CVE initially indicated the issue was resolved in version 1.10, testing confirmed the vulnerability remained present through version 1.14. The flaw was ultimately remedied in version 2.0. The practical risk of exploitation is considered low due to the technical complexity involved and existing protective mechanisms in modern systems.
Based on public CVE data (MITRE/NVD).