CVE · High

CVE-2022-1565 — WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-1565 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 Unrestricted Upload of File with Dangerous Type High 7.2 < 3.6.8 3.6.8 2022-06-30

CVE-2022-1565

The WP All Import plugin through version 3.6.7 contains a file upload vulnerability in the wp_all_import_get_gz.php file caused by insufficient validation of uploaded file types. Authenticated users with administrator privileges or higher can exploit this flaw to upload arbitrary files to the server, potentially enabling remote code execution. This vulnerability was fixed in version 3.6.8.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.