CVE-2022-2146
MEDIUMImport CSV Files < 1.0 - Reflected Cross-Site Scripting and Cross-Site Request Forgery
Title source: llmDescription
The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting
References (1)
Core 1
Core References
Exploit, Third Party Advisory exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/adc1d752-331e-44af-b5dc-b463d56c2cb4
Scores
CVSS v3
6.1
EPSS
0.0034
EPSS Percentile
25.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-352
Status
published
Products (1)
import_csv_files_project/import_csv_files
< 1.0
Published
Jul 17, 2022
Tracked Since
Feb 18, 2026