Beveiligingsadvies

CVE-2025-8767

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-08-12 06:42:40
Laatst bijgewerkt 2026-04-08 16:33:08
Toegewezen door Wordfence
CVSS-score 4.8
Status PUBLISHED

Beschrijving

The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16.17 via the 'download_csv_players' and 'download_csv_games' functions. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.