CVE-2022-1565

HIGH

Wpallimport WP All Import < 3.6.8 - Unrestricted File Upload

Title source: rule

Description

The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.

Exploits (2)

exploitdb WORKING POC VERIFIED
by AkuCyberSec · pythonwebappsphp
https://www.exploit-db.com/exploits/51122
nomisec WORKING POC
by phanthibichtram12 · poc
https://github.com/phanthibichtram12/CVE-2022-1565

Scores

CVSS v3 7.2
EPSS 0.5183
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
wpallimport/wp_all_import < 3.6.8
wpallimport/WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets < 3.6.7
Published Jul 18, 2022
Tracked Since Feb 18, 2026