7.2
CVSSv3

CVE-2022-3243

Published: 17/10/2022 Updated: 07/06/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The Import all XML, CSV & TXT WordPress plugin prior to 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

smackcoders import all pages\\, post types\\, products\\, orders\\, and users as xml \\& csv