Impact
The vulnerability in the WordPress Post Export Import with Media plugin allows authenticated attackers with administrator-level access to exploit a directory traversal flaw. By uploading a specially crafted ZIP archive that contains a media_metadata.json file with back‑door path traversal sequences in the 'file_path' field, an attacker can cause the plugin to read the contents of any file on the server. The flaw results in the disclosure of potentially sensitive data without requiring elevated system privileges, and the weakness is classified as CWE‑22.
Affected Systems
WordPress sites running the Post Export Import with Media plugin, versions up to and including 1.17.1, are affected. The issue is present in all builds before 1.18, and any site that has not yet upgraded beyond the 1.17.1 release remains vulnerable.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and the EPSS score is not currently available, suggesting the exploitation probability is not well quantified. The attack requires a valid administrator account to upload the malicious ZIP, implying that ordinary users cannot exploit it. However, within the administrative role, the path traversal can be leveraged to read arbitrary files, thereby granting the attacker access to sensitive information. Because the flaw is tied to an authenticated context, the risk is concentrated in environments where administrative privileges are broadly granted or not tightly controlled; the plugin does not permit anonymous exploitation.
OpenCVE Enrichment