CVE-2023-41798Improper Neutralization of Formula Elements in a CSV File in Directorist Wordpress Business Directory Plugin With Classified ADS Listings

Severity
8.8HIGHNVD
EPSS
0.7%
top 28.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 7

Description

Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

2
CVEList
WordPress Directorist Plugin <= 7.7.1 is vulnerable to CSV Injection2023-11-07
GHSA
GHSA-gpjf-v934-73g5: Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads2023-11-07
CVE-2023-41798 — HIGH severity | cvebase