Vulnerability CVE-2022-1273


Published: 2022-05-02

Description:
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE

Type:

CWE-434

(Unrestricted Upload of File with Dangerous Type)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Importwp -> Import wp 

 References:
https://wpscan.com/vulnerability/ad99b9ba-5f24-4682-a787-00f0e8e32603

Copyright 2024, cxsecurity.com

 

Back to Top