PT-2026-1010 · WordPress · Wp Import – Ultimate Csv Xml Importer

Dieu Link

+1

·

Publicado

2026-01-01

·

Atualizado

2026-01-01

·

CVE-2025-14627

CVSS v3.1

6.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Import – Ultimate CSV XML Importer for WordPress versions prior to 7.36
Description The plugin is susceptible to Server-Side Request Forgery (SSRF). This occurs because the plugin does not properly validate URLs after following Bitly shortlink redirects within the upload function() method. Specifically, the unshorten bitly url() function follows redirects without re-validating the final destination URL, allowing attackers to potentially make the server perform HTTP requests to arbitrary internal endpoints. This could include access to localhost, private IP ranges, and cloud metadata services. An authenticated attacker with Contributor-level access or higher can exploit this issue.
Recommendations Update to version 7.36 or later.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14627

Produtos afetados

Wp Import – Ultimate Csv Xml Importer