WP Ultimate CSV Importer <= 3.7 - Arbitrary File Read

2015-04-27 00:00
James Golovich

Vulnerability Overview

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the templates/readfile.php file in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to read any files on the vulnerable service that PHP has access to.

Technical Analysis

REMEDIATION: Update to version 3.7.1, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C