PT-2024-15204 · WordPress · Import Any Xml/Csv File To Wordpress

Quangnt

·

Published

2024-01-22

·

Updated

2024-01-26

·

CVE-2023-7082

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Import any XML or CSV File to WordPress plugin versions prior to 3.7.3
Description The issue allows high privilege users, such as administrators, to upload executable file types, potentially leading to remote code execution. This is due to the plugin accepting all zip files and automatically extracting them into a publicly accessible directory without sufficiently validating the extracted file type.
Recommendations For versions prior to 3.7.3, update to version 3.7.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the zip file upload feature to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-7082

Affected Products

Import Any Xml/Csv File To Wordpress