CVE-2022-3243
PoC —CVSS 3.1
7.2 high
EPSS
1%p63
Published
()
Modified
Description
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
- Vendors
- smackcoders
- Products
- import all pages\, post types\, products\, orders\, and users as xml \& csv
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.