CVE-2022-3677
05.12.2022, 17:15
The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacksEnginsight
Vendor | Product | Version |
---|---|---|
addonspress | advanced_import | 𝑥 < 1.3.8 |
𝑥
= Vulnerable software versions