CVE-2022-1565
HIGHWpallimport WP All Import < 3.6.8 - Unrestricted File Upload
Title source: ruleDescription
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by AkuCyberSec · pythonwebappsphp
https://www.exploit-db.com/exploits/51122
References (3)
Scores
CVSS v3
7.2
EPSS
0.5183
EPSS Percentile
97.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (2)
wpallimport/wp_all_import
< 3.6.8
wpallimport/WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
< 3.6.7
Published
Jul 18, 2022
Tracked Since
Feb 18, 2026