Back

HIGH

WP All Import < 3.6.8 - Admin+ Arbitrary File Upload

Published Jul 4, 2022

Description

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Jul 4, 2022
Updated Aug 3, 2024
Reserved Jun 30, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Jul 4, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-34543