First published: Tue Jan 18 2022(Updated: )
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vjinfotech WP Import Export | <=3.9.15 | |
VJInfotech WP Import Export Lite | <=3.9.15 |
Update to version 3.9.16, or newer.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0236 is a vulnerability found in the WP Import Export WordPress plugin that allows unauthenticated users to access sensitive data.
CVE-2022-0236 has a severity rating of 7.5 (high).
Versions up to and including 3.9.15 of both the free and premium versions of WP Import Export plugin are affected by CVE-2022-0236.
CVE-2022-0236 belongs to the CWE-862 category.
To fix CVE-2022-0236, update WP Import Export plugin to a version higher than 3.9.15.