WP Import Export Lite, 28b06084-67a0-466d-8030-5feddbafdfe2
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- WP Import Export Lite [wp-import-export-lite] < 3.9.5 WP Import Export Lite < 3.9.5 - Subscriber+ Arbitrary Blog Options Update The plugin does not have any CSRF and authorisation checks done in the wpie_ext_save_extension_data AJAX action, nor do perform any validation on the option to be updated. As a result, any authenticated user such as subscriber, or an unauthenticated attacker via a CSRF could update any of the blog options (set to the serialized POST data) which could make the blog and its plugins unusable.
- Affected versions
-
max 3.9.5.
- Status
-
vulnerable