ZeroHour

CVE-2022-3243

PoC
CVSS 3.1
7.2 high
EPSS
1%p63
Published
()
Modified
Description

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

Vendors
smackcoders
Products
import all pages\, post types\, products\, orders\, and users as xml \& csv
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.