cleantalk
Vulnerabilities and Security Researches

WP Import Export Lite, b5a8a4d1-61d9-46dd-8f52-321758172788

Application

WP Import Export Lite

Published on
-
Research Description
WP Import Export Lite [wp-import-export-lite] < 3.9.5 WP Import Export Lite &lt; 3.9.5 - Subscriber+ Extensions Update The plugin does not have any CSRF and authorisation checks done in wpie_ext_save_extensions AJAX action. This could allow any authenticated user such as subscriber, or an unauthenticated attacker via a CSRF to set the extensions to be used by the plugin, as well as disable all of them
Affected versions
max 3.9.5.
Status
vulnerable