CVE Database /
CVE-2022-36386
CVE · Critical
CVE-2022-36386 — WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-36386
|
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.1
|
< 3.6.8
|
3.6.8 |
2022-06-28 |
—
|
CVE-2022-36386
The WP All Import plugin before version 3.6.8 contains an arbitrary code execution vulnerability that could enable an attacker to remotely execute malicious code on affected WordPress sites. Successful exploitation could result in complete website compromise or the creation of additional backdoors for persistent access. The vulnerability was discovered by Universe and has been remedied in version 3.6.8 and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings