cleantalk
Vulnerabilities and Security Researches

WP Import Export Lite, 28b06084-67a0-466d-8030-5feddbafdfe2

Application

WP Import Export Lite

Published on
-
Research Description
WP Import Export Lite [wp-import-export-lite] < 3.9.5 WP Import Export Lite &lt; 3.9.5 - Subscriber+ Arbitrary Blog Options Update The plugin does not have any CSRF and authorisation checks done in the wpie_ext_save_extension_data AJAX action, nor do perform any validation on the option to be updated. As a result, any authenticated user such as subscriber, or an unauthenticated attacker via a CSRF could update any of the blog options (set to the serialized POST data) which could make the blog and its plugins unusable.
Affected versions
max 3.9.5.
Status
vulnerable