CVE-2022-45370: WordPress WordPress Comments Import & Export plugin <= 2.3.1 - CSV Injection
Published Nov 7, 2023
·Updated
A vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce.This issue affects Comments Import & Export: from n/a through <= 2.3.1.
Affected Software
1 affected component
WebToffee Wordpress Comments Import And Export Wordpress<=2.3.1
Remediation
Information
Update to 2.3.2 or a higher version.
Event History
Nov 7, 2023
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-45370.
2
What is the severity of CVE-2022-45370?
The severity of CVE-2022-45370 is critical with a severity value of 9.8.
3
What is the affected software for CVE-2022-45370?
The affected software for CVE-2022-45370 is WebToffee WordPress Comments Import & Export version up to and including 2.3.1.
4
What is the CWE for CVE-2022-45370?
The CWE for CVE-2022-45370 is 1236.
5
How do I fix CVE-2022-45370?
To fix CVE-2022-45370, it is recommended to update WebToffee WordPress Comments Import & Export to a version beyond 2.3.1 or apply any available patches or fixes provided by the vendor.