Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown

CVE-2023-0254

Disclosure Date: January 12, 2023 (last updated October 08, 2023)
The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2022-40209

Disclosure Date: December 06, 2022 (last updated November 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xylus Themes WP Smart Import plugin <= 1.0.2 on WordPress.
Attacker Value
Unknown

CVE-2022-2711

Disclosure Date: November 07, 2022 (last updated December 22, 2024)
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.
Attacker Value
Unknown

CVE-2022-3418

Disclosure Date: November 07, 2022 (last updated December 22, 2024)
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files
Attacker Value
Unknown

CVE-2022-2669

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2022-1565

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.
Attacker Value
Unknown

CVE-2022-2268

Disclosure Date: July 04, 2022 (last updated February 24, 2025)
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
Attacker Value
Unknown

CVE-2022-36386

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
Attacker Value
Unknown

CVE-2022-1273

Disclosure Date: May 02, 2022 (last updated February 23, 2025)
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE
Attacker Value
Unknown

CVE-2022-0236

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.