CVE-2022-1273

The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:importwp:import_wp:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-05-02 09:15

Updated : 2022-05-10 12:17


NVD link : CVE-2022-1273

Mitre link : CVE-2022-1273


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

Advertisement

dedicated server usa

Products Affected

importwp

  • import_wp