The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16.17 via the 'download_csv_players' and 'download_csv_games' functions. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
History

Tue, 12 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Anwp
Anwp football Leagues
Wordpress
Wordpress wordpress
Vendors & Products Anwp
Anwp football Leagues
Wordpress
Wordpress wordpress

Tue, 12 Aug 2025 06:45:00 +0000

Type Values Removed Values Added
Description The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16.17 via the 'download_csv_players' and 'download_csv_games' functions. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Title AnWP Football Leagues <= 0.16.17 - Authenticated (Administrator+) CSV Injection
Weaknesses CWE-1236
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-08-12T06:42:40.577Z

Updated: 2025-08-12T20:07:51.764Z

Reserved: 2025-08-08T18:17:14.475Z

Link: CVE-2025-8767

cve-icon Vulnrichment

Updated: 2025-08-12T20:07:38.437Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-12T07:15:30.733

Modified: 2025-08-12T14:25:33.177

Link: CVE-2025-8767

cve-icon Redhat

No data.