PT-2025-29320 · WordPress · Ait Csv Import/Export

Published

2025-07-12

·

Updated

2026-03-04

·

CVE-2020-36849

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: AIT CSV import/export plugin for WordPress versions up to and including 3.0.3
Description: The AIT CSV import/export plugin for WordPress is susceptible to arbitrary file uploads due to a lack of file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file. This allows unauthorized attackers to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations: Versions prior to 3.0.4: Update the AIT CSV import/export plugin to a version later than 3.0.3.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-36849

Affected Products

Ait Csv Import/Export