2 results (0.002 seconds)

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 0

17 Jun 2024 — The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. El complemento Business Directory Plugin para WordPress es vulnerable a la iny... • https://plugins.trac.wordpress.org/browser/business-directory-plugin/trunk/includes/admin/class-csv-exporter.php • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

28 Nov 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows Cross-Site Request Forgery.This issue affects Business Directory Plugin – Easy Listing Directories for WordPress: from n/a through 6.3.10. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress permite Cross-Site Request Forgery. Este problema afecta a Business Directory ... • https://patchstack.com/database/vulnerability/business-directory-plugin/wordpress-business-directory-plugin-easy-listing-directories-for-wordpress-plugin-6-3-10-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •