Code Injection in WooCommerce - Store Exporter - #VU24185
Published: January 10, 2020
WooCommerce - Store Exporter
Detailed vulnerability description
The vulnerability exists due to insufficient sanitization of user-supplied data when constructing CSV files. A remote user can inject a command that will be included in the exported CSV file and execute arbitrary command/code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.