cleantalk
Vulnerabilities and Security Researches

Import CSV or XML Datafeed With Ease, fc4865d1-00b9-4594-99d2-e2a3fc0d3951

Published on
-
Research Description
WP Ultimate CSV Importer – WordPress CSV, XML &amp; Excel Import Export [wp-ultimate-csv-importer] < 3.6.75 WP Ultimate CSV Importer &lt;= 3.6.74 - Database Table Export Due to lack of verification of a visitors permissions, it is possible to execute the &lsquo;export.php&rsquo; script included in the default installation of this plugin, and retrieve the full contents of the user table in the WordPress installation. This results in full disclosure of usernames, hashed passwords and email addresses for all users. After update 3.6.74, a change to the &lsquo;export.php&rsquo; script was made, which required a REFERER header to be passed through in the request. After this header is added (as in the second PoC), the behaviour is exactly the same, resulting in full disclosure of usernames, hashed passwords and email addresses for all users.
Affected versions
max 3.6.75.
Status
vulnerable