Lucene search

K
cvelistWPScanCVELIST:CVE-2022-3418
HistoryNov 07, 2022 - 12:00 a.m.

CVE-2022-3418 WP All Import < 3.6.9 - Admin+ Arbitrary File Upload to RCE

2022-11-0700:00:00
CWE-94
WPScan
www.cve.org
2
cve-2022-3418
wp all import
arbitrary file upload
rce
multi-site wordpress

EPSS

0.001

Percentile

44.9%

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Import any XML or CSV File to WordPress",
    "versions": [
      {
        "version": "3.6.9",
        "status": "affected",
        "lessThan": "3.6.9",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

44.9%

Related for CVELIST:CVE-2022-3418