The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-11-07T00:00:00
Updated: 2024-08-03T01:07:06.584Z
Reserved: 2022-10-07T00:00:00
Link: CVE-2022-3418
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-11-07T10:15:11.647
Modified: 2022-11-09T20:06:08.563
Link: CVE-2022-3418
Redhat
No data.