3.5
CVSSv2

CVE-2022-0360

Published: 28/02/2022 Updated: 07/06/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin prior to 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

smackcoders import all pages\\, post types\\, products\\, orders\\, and users as xml \\& csv