← back
CVE-2022-2798

Affiliates Manager < 2.9.14 - Affiliate CSV Injection

EPSS 0.9%CWE-1236
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →