Import any XML or CSV File to WordPress <= 3.2.4 - Missing Authorization and Cross-Site Request Forgery Checks

2020-02-19 00:00
Kacper Szurek

Strategic Overview

Status
Patched in 4.1.2
Affected PluginWP All Import Pro
Affected Version<= 4.1.1
CVSS6.3Medium
CVEN/A
View all WP All Import Pro vulnerabilities

Vulnerability Overview

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.2.4 due to missing capability and nonce checks on various functions.

Technical Analysis

REMEDIATION: Update to version 4.1.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C