CVE Database /
CVE-2022-1565
CVE · High
CVE-2022-1565 — WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-1565
|
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 |
Unrestricted Upload of File with Dangerous Type |
High
7.2
|
< 3.6.8
|
3.6.8 |
2022-06-30 |
—
|
CVE-2022-1565
The WP All Import plugin through version 3.6.7 contains a file upload vulnerability in the wp_all_import_get_gz.php file caused by insufficient validation of uploaded file types. Authenticated users with administrator privileges or higher can exploit this flaw to upload arbitrary files to the server, potentially enabling remote code execution. This vulnerability was fixed in version 3.6.8.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings