HIGH
WP All Import < 3.6.8 - Admin+ Arbitrary File Upload
Published Jul 4, 2022
7.2
HIGHCVSS 3.1
EPSS 1.42%
Description
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
Affected products
- Vendor n/a Product Import any XML or CSV File to WordPress Defaultn/a
- Version 3.6.8StatusaffectedConstraints<3.6.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Import any XML or CSV File to WordPress | n/a |
|
- < 3.6.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34543 Advisory
- https://wpscan.com/vulnerability/578093db-a025-4148-8c4b-ec2df31743f7 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34543 | Advisory | |
| https://wpscan.com/vulnerability/578093db-a025-4148-8c4b-ec2df31743f7 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Jul 4, 2022
Updated Aug 3, 2024
Reserved Jun 30, 2022
Link CVE-2022-2268
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-34543 Assigner WPScan
Published Jul 4, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-34543