First published: Mon Feb 28 2022(Updated: )
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Smackcoders Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv | <6.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0360 is a vulnerability in the Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before version 6.4.3.
The severity of CVE-2022-0360 is rated as medium.
CVE-2022-0360 could allow high privilege users to import malicious comments and result in Stored Cross-Site Scripting (XSS) issues.
CVE-2022-0360 can be exploited by importing malicious comments with unescaped content.
To fix CVE-2022-0360, you should update the Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin to version 6.4.3 or later.