{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-04T09:26:05.619","vulnerabilities":[{"cve":{"id":"CVE-2025-8767","sourceIdentifier":"security@wordfence.com","published":"2025-08-12T07:15:30.733","lastModified":"2026-06-17T10:07:35.440","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16.17 via the 'download_csv_players' and 'download_csv_games' functions. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration."},{"lang":"es","value":"El complemento AnWP Football Leagues para WordPress es vulnerable a la inyección de CSV en todas las versiones hasta la 0.16.17 incluida, a través de las funciones «download_csv_players» y «download_csv_games». Esto permite a atacantes autenticados, con acceso de administrador o superior, incrustar información no confiable en archivos CSV exportados, lo que puede provocar la ejecución de código al descargar y abrir estos archivos en un sistema local con una configuración vulnerable."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"anwppro","product":"AnWP Football Leagues","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.16.17","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-12T20:06:56.458368Z","id":"CVE-2025-8767","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1236"}]}],"references":[{"url":"http://plugins.trac.wordpress.org/changeset/3342787/football-leagues-by-anwppro/trunk/includes/class-anwpfl-data-port.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/football-leagues-by-anwppro/trunk/includes/class-anwpfl-data-port.php#L265","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/football-leagues-by-anwppro/trunk/includes/class-anwpfl-data-port.php#L58","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/football-leagues-by-anwppro/trunk/includes/class-anwpfl-data-port.php#L93","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/04676263-cdad-40cd-bb54-61beb727e09d?source=cve","source":"security@wordfence.com"}]}}]}