WP Ultimate CSV Importer <= 6.4.0 - Arbitrary File Upload
2022-01-12 00:00
AnonymousStrategic Overview
StatusPatched in 6.4.1
Affected Version
<= 6.4.0CVSS8.8High
CVE
N/AVulnerability Overview
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip_upload AJAX call in versions up to, and including, 6.4.0. This makes it possible for subscriber-level attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Technical Analysis
REMEDIATION: Update to version 6.4.1, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C