CVE-2022-3243
Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 Oct 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Import all XML, CSV & TXT into WordPressWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →