The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-11-07T00:00:00
Updated: 2024-08-03T00:46:03.827Z
Reserved: 2022-08-08T00:00:00
Link: CVE-2022-2711
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-11-07T10:15:11.480
Modified: 2022-11-09T20:04:59.287
Link: CVE-2022-2711
Redhat
No data.