CVE-2022-1977: WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF
Published Jun 27, 2022
·Updated
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks
Affected Software
1 affected component
Smackcoders Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv<6.5.3
Event History
Jun 27, 2022
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-1977.
2
What is the severity of CVE-2022-1977?
The severity of CVE-2022-1977 is high with a score of 7.2.
3
What is the affected software for CVE-2022-1977?
The affected software for CVE-2022-1977 is the Import Export All WordPress Images, Users & Post Types WordPress plugin before version 6.5.3.
4
What is the CWE ID for CVE-2022-1977?
The CWE ID for CVE-2022-1977 is CWE-918.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by high privilege users, such as admin, to perform Blind SSRF attacks.