The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42795 | The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-01T20:44:44.308Z
Reserved: 2022-10-07T00:00:00.000Z
Link: CVE-2022-3418
Updated: 2024-08-03T01:07:06.584Z
Status : Modified
Published: 2022-11-07T10:15:11.647
Modified: 2025-05-01T21:15:50.940
Link: CVE-2022-3418
No data.
OpenCVE Enrichment
No data.
EUVD