CVE-2022-3243: Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi
Published Oct 17, 2022
·Updated
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
Affected Software
1 affected component
Smackcoders Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv<6.5.8
Event History
Oct 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3243.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The Import all XML CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imp…'
3
What is the affected software?
The affected software is the Import all XML, CSV & TXT WordPress plugin before version 6.5.8.
4
What is the severity of CVE-2022-3243?
The severity of CVE-2022-3243 is high.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by high privilege users, such as admin, through SQL injection.