Web / CMS

SQL / NoSQL Injection

Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi

Import all XML, CSV & TXT into WordPress < 6.5.8 – Admin+ SQLi The plugin does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection…

7.2
/ 10
High
CVSS v3.1
ADVISORY ID
PS60
PUBLISHED
2023-01-18
CVE IDs
CVE-2022-3243
VENDORS
Smackcoders
PUBLIC EXPLOIT
PoC public
CWE
CWE-89
PRODUCT
WP Ultimate CSV Importer (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Import all XML, CSV & TXT into WordPress < 6.5.8 – Admin+ SQLi

The plugin does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

Vulnerability details

Vulnerability details

CVE-2022-3243
CWE-89
High | 7.2

Import all XML, CSV & TXT into WordPress < 6.5.8 – Admin+ SQLi The plugin does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

Auth:
Administrative privileges (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2022-07-27 Reported On

2022-09-20 Made Public On

2022-08-26 Fixed On

Credits

Sanjay Das