PT-2024-14815 · WordPress · The Business Directory Plugin

·

CVE-2023-5527

·

Published

2024-06-18

·

Updated

2024-07-05

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Business Directory Plugin plugin for WordPress versions up to, and including, 6.4.3
Description The issue allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. The vulnerability is exploited via the class-csv-exporter.php file.
Recommendations For versions up to, and including, 6.4.3, consider disabling the class-csv-exporter.php file or restricting access to it until a patch is available. As a temporary workaround, administrators should avoid downloading and opening CSV files exported from the plugin on local systems with vulnerable configurations.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-5527

Affected Products

The Business Directory Plugin