VulnerabilityModified
CVE-2022-3244
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce
MEDIUM 4.2EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce
- CVSS 3.1
- 4.2 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- smackcoders/import all pages\, post types\, products\, orders\, and users as xml \& csv
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/de4bc449-3dd4-4776-943f-ac59ae813132Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/de4bc449-3dd4-4776-943f-ac59ae813132Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.