CVE-2023-7082
22.01.2024, 20:15
The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessible directory without sufficiently validating the extracted file type. This may allows high privilege users such as administrator to upload an executable file type leading to remote code execution.Enginsight
| Vendor | Product | Version |
|---|---|---|
| soflyy | export_any_wordpress_data_to_xml\/csv | 𝑥 < 3.7.3 |
𝑥
= Vulnerable software versions