Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Quangnt

#38242of 53,624
7.2Total CVSS
Vulnerabilities · 1
PT-2024-15204
7.2
2024-01-22
WordPress · Import Any Xml/Csv File To Wordpress · CVE-2023-7082
**Name of the Vulnerable Software and Affected Versions** Import any XML or CSV File to WordPress plugin versions prior to 3.7.3 **Description** The issue allows high privilege users, such as administrators, to upload executable file types, potentially leading to remote code execution. This is due to the plugin accepting all zip files and automatically extracting them into a publicly accessible directory without sufficiently validating the extracted file type. **Recommendations** For versions prior to 3.7.3, update to version 3.7.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the zip file upload feature to minimize the risk of exploitation.