PT-2022-13754 · WordPress · Export/Import Users/Customers

0X23.So

·

Published

2022-05-02

·

Updated

2022-05-09

·

CVE-2022-1255

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Import and export users and customers WordPress plugin versions prior to 1.19.2.1
Description The issue arises from the plugin's failure to sanitise and escape imported CSV data, allowing high privilege users to import malicious javascript code. This can lead to Stored Cross-Site Scripting issues.
Recommendations For versions prior to 1.19.2.1, update to version 1.19.2.1 or later to resolve the issue. As a temporary workaround, consider restricting the import functionality to trusted users only until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1255

Affected Products

Export/Import Users/Customers