cleantalk
Vulnerabilities and Security Researches

Import WP – Export and Import CSV and XML files to WordPress, CVE-2022-1273

CVE, Research URL

CVE-2022-1273

Published on
May 02, 2022
Research Description
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE
Affected versions
max 2.4.6.
Status
vulnerable