CVE-2022-0360
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored…
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- smackcoders/import all pages\, post types\, products\, orders\, and users as xml \& csv
- Source
- contact@wpscan.com
References
- https://plugins.trac.wordpress.org/changeset/2662897Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/d718b993-4de5-499c-84c9-69801396f51fExploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2662897Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/d718b993-4de5-499c-84c9-69801396f51fExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.