PT-2022-22047 · WordPress · Import Any Xml/Csv File To Wordpress

Lucy

·

Published

2022-11-07

·

Updated

2022-11-09

·

CVE-2022-3418

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Import any XML or CSV File to WordPress plugin versions prior to 3.6.9
Description The issue arises from the plugin not properly filtering allowed file extensions for import on the server. This could allow administrators in multi-site WordPress installations to upload arbitrary files.
Recommendations For versions prior to 3.6.9, update to version 3.6.9 or later to resolve the issue.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-3418

Affected Products

Import Any Xml/Csv File To Wordpress