NA

CVE-2022-2711

Published: 07/11/2022 Updated: 09/11/2022
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The Import any XML or CSV File to WordPress plugin prior to 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

soflyy wp all import