Advanced Import : One Click Import for WordPress or Theme Demo Data, CVE-2022-3677
- CVE, Research URL
- Home page URL
-
Security reports for Advanced Import : One Click Import for WordPress or Theme Demo Data
- Published on
- Dec 05, 2022
- Research Description
- The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks
- Affected versions
-
max 1.3.8.
- Status
-
vulnerable