CVE-2022-1565
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.
El plugin WP All Import es vulnerable a ua carga de archivos arbitrarios debido a una falta de comprobación del tipo de archivo por medio del archivo wp_all_import_get_gz.php en versiones hasta 3.6.7 incluyéndola. Esto hace posible que atacantes autenticados, con permisos de nivel de administrador y superiores, suban archivos arbitrarios en el servidor de los sitios afectados, lo que puede hacer posible una ejecución de código remota
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-03 CVE Reserved
- 2022-06-30 CVE Published
- 2023-03-29 First Exploit
- 2024-08-03 CVE Updated
- 2024-12-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/threat-intel/vulnerabilities/id/5d281333-d9af-4eb7-bc5c-ea7ceeddac03?source=cve | Third Party Advisory | |
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1565 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/51122 | 2023-03-29 | |
https://github.com/phanthibichtram12/CVE-2022-1565 | 2024-06-21 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2749264/wp-all-import/trunk?contextall=1&old=2737093&old_path=%2Fwp-all-import%2Ftrunk | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpallimport Search vendor "Wpallimport" | Wp All Import Search vendor "Wpallimport" for product "Wp All Import" | < 3.6.8 Search vendor "Wpallimport" for product "Wp All Import" and version " < 3.6.8" | wordpress |
Affected
|