PT-2022-21317 · WordPress · Import All Xml

P3N7A90N

+1

·

Published

2022-10-17

·

Updated

2025-05-14

·

CVE-2022-3243

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Import all XML, CSV & TXT WordPress plugin versions prior to 6.5.8
Description The issue is related to the improper sanitization and escaping of imported data, which is then used in SQL statements. This leads to SQL injection, a type of attack where an attacker can execute malicious SQL code. The exploitation of this issue is possible by high-privilege users, such as administrators.
Recommendations For versions prior to 6.5.8, update to version 6.5.8 or later to resolve the issue. As a temporary workaround, consider restricting the import functionality to minimize the risk of exploitation. Avoid using the import feature with untrusted data until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-3243

Affected Products

Import All Xml