WP Import Export (Lite) <= 3.9.15 Unauthenticated Sensitive Data Disclosure
Published Jan 18, 2022
7.5
HIGHCVSS 3.1
EPSS 4.28%
Description
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.
Affected products
-
- Version 3.9.15StatusaffectedConstraints<=3.9.15
- Version
-
- Version 3.9.15StatusaffectedConstraints<=3.9.15
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vjinfotech | WP Import Export | n/a |
| ||||||
| Vjinfotech | WP Import Export Lite | n/a |
|
- ≤ 3.9.15
- ≤ 3.9.15
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to version 3.9.16, or newer.
References (3)
- https://github.com/qurbat/CVE-2022-0236 x_refsource_MISCExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2649762/wp-import-export-lite/trunk/includes/classes/class-wpie-general.php x_refsource_MISCPatchThird Party Advisory
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0236 x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/qurbat/CVE-2022-0236 | x_refsource_MISCExploitThird Party Advisory | |
| https://plugins.trac.wordpress.org/changeset/2649762/wp-import-export-lite/trunk/includes/classes/class-wpie-general.php | x_refsource_MISCPatchThird Party Advisory | |
| https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0236 | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.