WP Import Export Lite, b5a8a4d1-61d9-46dd-8f52-321758172788
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- WP Import Export Lite [wp-import-export-lite] < 3.9.5 WP Import Export Lite < 3.9.5 - Subscriber+ Extensions Update The plugin does not have any CSRF and authorisation checks done in wpie_ext_save_extensions AJAX action. This could allow any authenticated user such as subscriber, or an unauthenticated attacker via a CSRF to set the extensions to be used by the plugin, as well as disable all of them
- Affected versions
-
max 3.9.5.
- Status
-
vulnerable