Web / CMS

Authentication & Access Bypass

Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisation

Import all XML, CSV & TXT into WordPress < 6.5.8 – Missing Authorisation The plugin does not have authorisation in some places, which could allow any authenticated users to access some of the plugin

4.2
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS61
PUBLISHED
2023-02-06
CVE IDs
CVE-2022-3244
VENDORS
Smackcoders
PUBLIC EXPLOIT
PoC public
CWE
CWE-862
PRODUCT
WP Ultimate CSV Importer (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Import all XML, CSV & TXT into WordPress < 6.5.8 – Missing Authorisation

The plugin does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce

Vulnerability details

Vulnerability details

CVE-2022-3244
CWE-862
Medium | 4.2

Import all XML, CSV & TXT into WordPress < 6.5.8 – Missing Authorisation The plugin does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce

Auth:
Any authenticated user (remote)
Impact:
Limited data disclosure, limited data tampering
DISCLOSURE

Disclosure timeline

2022-07-27 Reported On

2022-09-20 Made Public On

2022-08-26 Fixed On

Credits

Sanjay Das