7.5

CVE-2022-0236

Exploit

WP Import Export (Lite) <= 3.9.15 Unauthenticated Sensitive Data Disclosure

WP Import Export Lite & WP Import Export <= 3.9.15 - Unauthenticated Sensitive Data Disclosure

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.
Mögliche Gegenmaßnahme
WP Import Export Lite: Update to version 3.9.16, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VjinfotechWp Import Export SwPlatformwordpress Version <= 3.9.15
VjinfotechWp Import Export Lite SwPlatformwordpress Version <= 3.9.15
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP Import Export Lite
Version *-3.9.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.28% 0.898
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
security@wordfence.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://github.com/qurbat/CVE-2022-0236
Third Party Advisory
Exploit
https://plugins.trac.wordpress.org/changeset/2649762/wp-import-export-lite/trunk/includes/classes/class-wpie-general.php
Patch
Third Party Advisory
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0236
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/4c9cbe99-699a-4812-a8ae-aefd2b1e2c00
Third Party Advisory