Web / CMS
SQL / NoSQL Injection
Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi
Import all XML, CSV & TXT into WordPress < 6.5.8 – Admin+ SQLi The plugin does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection…
.png)
Overview
Import all XML, CSV & TXT into WordPress < 6.5.8 – Admin+ SQLi
The plugin does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
Vulnerability details
Import all XML, CSV & TXT into WordPress < 6.5.8 – Admin+ SQLi The plugin does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
Disclosure timeline
2022-07-27 Reported On
2022-09-20 Made Public On
2022-08-26 Fixed On
References
Credits
Sanjay Das
















