The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2022-10-17T00:00:00.000Z
Updated: 2025-05-14T20:17:07.691Z
Reserved: 2022-09-20T00:00:00.000Z
Link: CVE-2022-3243

Updated: 2024-08-03T01:00:10.864Z

Status : Modified
Published: 2022-10-17T12:15:10.597
Modified: 2025-05-14T21:15:53.913
Link: CVE-2022-3243

No data.