ZeroHour

CVE-2022-1977

PoC
CVSS 3.1
7.2 high
EPSS
1%p69
Published
()
Modified
Description

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

Vendors
smackcoders
Products
import all pages\, post types\, products\, orders\, and users as xml \& csv
Ecosystems
WordPress
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.