CVE Database /
CVE-2022-3600
CVE · Critical
CVE-2022-3600 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3600
|
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.1.0.2 |
Improper Neutralization of Formula Elements in a CSV File |
Critical
9.8
|
< 3.1.0.2
|
3.1.0.2 |
2022-09-28 |
—
|
CVE-2022-3600
The Easy Digital Downloads plugin for WordPress before version 3.1.0.2 contains a CSV injection vulnerability that allows unauthenticated attackers to insert malicious content into exported CSV files. When a user downloads and opens these compromised files in a spreadsheet application with vulnerable settings, the embedded code can execute on their local system, potentially compromising their security.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings