← Back to CVE List

CVE-2022-2798

Published: 2022-09-16T09:15Z
Last Modified: 2024-11-21T07:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data > MITRE Terms of Use apply – see LICENSE‑MITRE.txt