Record summary

CVE-2019-17232 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 30, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Ultimate FAQs <= 1.8.24 – Unauthenticated Options Import and ExportCVSS 7.5

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

Impact

Unauthenticated attackers can import arbitrary FAQs and configuration through CSV upload, potentially injecting malicious content or extracting existing FAQ data from the WordPress site.

Remediation

Update the Ultimate FAQs plugin to version 1.8.25 or later.

WeaknessesCWE-306
Authorsdaffainfo
Template tagscvecve2019wordpresswp-pluginwpultimate-faqsunauthintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CPE: cpe:2.3:a:etoilewebdesign:ultimate_faq:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/ultimate-faqs"
FOFA: body="/wp-content/plugins/ultimate-faqs"

Source: ProjectDiscovery

References

4