PT-2022-14230 · WordPress · Import Export All Wordpress Images

Luan Pedersini

·

Published

2022-06-27

·

Updated

2023-06-07

·

CVE-2022-1977

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Import Export All WordPress Images, Users & Post Types WordPress plugin versions prior to 6.5.3
Description The issue concerns the lack of full validation for files to be imported via URL, which could allow high-privilege users, such as admins, to perform Blind SSRF (Server-Side Request Forgery) attacks. This occurs because the plugin makes an HTTP request to the file without properly checking its validity.
Recommendations For versions prior to 6.5.3, update to version 6.5.3 or later to resolve the issue. As a temporary workaround, consider restricting the import functionality to trusted sources or disabling it until the update is applied.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-1977

Affected Products

Import Export All Wordpress Images