Skip to main content

CVE-2025-8767: AnWP Football Leagues CSV Injection Flaw

CVE-2025-8767 is a CSV injection vulnerability in the AnWP Football Leagues WordPress plugin that allows attackers to embed malicious code in exported CSV files. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2025-8767 Overview

CVE-2025-8767 is a CSV Injection vulnerability affecting the AnWP Football Leagues plugin for WordPress in all versions up to and including 0.16.17. The flaw resides in the download_csv_players and download_csv_games export functions, which fail to sanitize untrusted input before writing it into exported CSV files. Authenticated attackers with Administrator-level access or above can embed spreadsheet formulas into stored data. When a downstream user opens the exported file in a spreadsheet application with a vulnerable configuration, those formulas execute in the local context. The issue is classified under [CWE-1236: Improper Neutralization of Formula Elements in a CSV File].

Critical Impact

Authenticated administrators can inject spreadsheet formulas into CSV exports, leading to code execution on the machines of users who open the file.

Affected Products

  • AnWP Football Leagues plugin for WordPress, versions 0.16.17 and earlier
  • download_csv_players export function in class-anwpfl-data-port.php
  • download_csv_games export function in class-anwpfl-data-port.php

Discovery Timeline

  • 2025-08-12 - CVE-2025-8767 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8767

Vulnerability Analysis

CSV Injection, sometimes called Formula Injection, occurs when applications write user-supplied strings into CSV files without neutralizing characters that spreadsheet software interprets as formula prefixes. Common trigger characters include =, +, -, @, tab, and carriage return. In the AnWP Football Leagues plugin, player and match data submitted through the WordPress backend flows directly into the export functions without escaping. When an administrator or another user downloads the CSV and opens it in Microsoft Excel, LibreOffice Calc, or Google Sheets, the crafted cell is parsed as a formula. Depending on the spreadsheet configuration, this can trigger calls to DDE, HYPERLINK, WEBSERVICE, or IMPORTXML handlers, enabling data exfiltration or command execution on the local system.

Root Cause

The root cause is the absence of output encoding in the CSV writer paths located at lines 58, 93, and 265 of class-anwpfl-data-port.php. The affected functions concatenate stored field values into CSV rows without prefixing potentially dangerous leading characters with a single quote or applying any allow-list filter. Because WordPress administrators can populate these fields directly, the plugin trusts data it should treat as untrusted at export time.

Attack Vector

Exploitation requires an authenticated attacker with Administrator-level privileges on the target WordPress site. The attacker stores a malicious payload such as =cmd|'/c calc'!A1 in a player or game field. A second user then triggers the export via download_csv_players or download_csv_games and opens the resulting file locally. User interaction from the victim is required, and successful exploitation depends on the victim's spreadsheet application permitting formula execution or external content prompts being accepted. Refer to the Wordfence Vulnerability Report for technical details.

Detection Methods for CVE-2025-8767

Indicators of Compromise

  • Player, team, or match fields in the AnWP Football Leagues database whose values begin with =, +, -, or @.
  • CSV exports containing cells that reference cmd, DDE, HYPERLINK, WEBSERVICE, or IMPORTXML calls.
  • Outbound DNS or HTTP requests from analyst workstations shortly after opening a plugin-generated CSV file.
  • Spawned child processes such as cmd.exe, powershell.exe, or bash from EXCEL.EXE, soffice.bin, or other spreadsheet binaries.

Detection Strategies

  • Scan the WordPress database for plugin table entries beginning with formula-trigger characters.
  • Inspect generated CSV files with a linter or grep pattern before distribution to users.
  • Monitor endpoint telemetry for spreadsheet applications spawning shells, script interpreters, or network utilities.
  • Correlate WordPress admin activity logs with subsequent CSV downloads to identify suspicious export chains.

Monitoring Recommendations

  • Enable WordPress audit logging on administrator accounts, including plugin export actions.
  • Alert on process-lineage anomalies where Office or spreadsheet software launches interpreters or LOLBins.
  • Review outbound network connections initiated by user workstations immediately after CSV file access.

How to Mitigate CVE-2025-8767

Immediate Actions Required

  • Update the AnWP Football Leagues plugin to a version above 0.16.17 once available from the vendor.
  • Restrict Administrator-level access to trusted personnel and enforce multi-factor authentication on WordPress admin accounts.
  • Sanitize existing plugin data by removing or escaping cells that begin with =, +, -, or @.
  • Warn users who receive CSV exports to open files in a protected view and to disable automatic formula and external content execution.

Patch Information

The vendor addressed the issue in the plugin trunk. Review the fix in the WordPress Plugin Changeset 3342787 and the pre-patch source at class-anwpfl-data-port.php line 265. Site operators should apply the latest plugin release through the WordPress admin dashboard or via WP-CLI.

Workarounds

  • Disable the AnWP Football Leagues plugin until an updated version is installed.
  • Route CSV exports through a sanitization proxy that prepends a single quote to cells starting with formula-trigger characters.
  • Configure spreadsheet clients to disable Dynamic Data Exchange (DDE) and to block external content by default via Group Policy.
bash
# Configuration example: update the plugin via WP-CLI once a fixed version is published
wp plugin update football-leagues-by-anwppro
wp plugin status football-leagues-by-anwppro

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.