Import WP – Import and Export WordPress data to XML or CSV files <= 2.4.5 - Authenticated Arbitrary File Upload
2022-04-11 00:00
ericfrank900528Strategic Overview
StatusPatched in 2.4.6
Affected PluginImport WP – Export and Import CSV and XML files to WordPress
Affected Version
<= 2.4.5CVSS7.2High
CVE
CVE-2022-1273Vulnerability Overview
The Import WP – Import and Export WordPress data to XML or CSV files plugin for WordPress is vulnerable to arbitrary file upload via high level authenticated users in versions up to, and including, 2.4.5.
Technical Analysis
REMEDIATION: Update to version 2.4.6, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C