CVE-2023-4139: WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated attackers to list and view exported files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4139?
CVE-2023-4139 is a vulnerability in the WP Ultimate CSV Importer plugin for WordPress that allows unauthenticated attackers to list and view exported files due to missing restriction in export folder indexing.
How severe is CVE-2023-4139?
CVE-2023-4139 has a severity rating of 7.5 (high).
Which versions of the WP Ultimate CSV Importer plugin for WordPress are affected by CVE-2023-4139?
Versions up to and including 7.9.8 of the WP Ultimate CSV Importer plugin for WordPress are affected by CVE-2023-4139.
How can unauthenticated attackers exploit CVE-2023-4139?
Unauthenticated attackers can exploit CVE-2023-4139 to list and view exported files by taking advantage of the missing restriction in export folder indexing.
Where can I find more information about CVE-2023-4139?
You can find more information about CVE-2023-4139 at the following references: 1. [Wordfence Threat Intel](https://www.wordfence.com/threat-intel/vulnerabilities/id/6404476e-0c32-4f8e-882f-6a1785ba5748?source=cve) 2. [WordPress Plugin Directory](https://plugins.trac.wordpress.org/changeset/2944635/wp-ultimate-csv-importer/trunk/wp-ultimate-csv-importer.php)