Security Advisory

CVE-2022-3243

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-10-17 00:00:00
Last updated 2025-05-14 20:17:07
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin