The Simple CSV Table plugin for WordPress contains a directory traversal vulnerability in versions up to and including 1.0.1. It allows authenticated users with Contributor-level access and above to access arbitrary files on the server by exploiting insufficient path validation in the `href` parameter of the `[csv]` shortcode.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.