CVE · Critical

CVE-2022-36386 — WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-36386 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 Improper Control of Generation of Code ('Code Injection') Critical 9.1 < 3.6.8 3.6.8 2022-06-28

CVE-2022-36386

The WP All Import plugin before version 3.6.8 contains an arbitrary code execution vulnerability that could enable an attacker to remotely execute malicious code on affected WordPress sites. Successful exploitation could result in complete website compromise or the creation of additional backdoors for persistent access. The vulnerability was discovered by Universe and has been remedied in version 3.6.8 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.