5
CVSSv2

CVE-2022-0236

Published: 18/01/2022 Updated: 24/01/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated malicious users to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vjinfotech wp import export

vjinfotech wp import export lite

Github Repositories

Proof of concept for unauthenticated sensitive data disclosure affecting the wp-import-export WordPress plugin (CVE-2022-0236)

CVE-2022-0236 The WP Import Export WordPress plugin is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-generalphp file This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable sit

CVE-2022-0236

CVE-2022-0236 CVE-2022-0236