CVE-2025-8767 – WordPress AnWP Football Leagues Plugin CSV Injection Vulnerability

CVE ID : CVE-2025-8767

Published : Aug. 12, 2025, 7:15 a.m. | 2 hours, 7 minutes ago

Description : The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16.17 via the ‘download_csv_players’ and ‘download_csv_games’ functions. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Severity: 4.8 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Share the Post:

Related Posts