Vulnerability Description
The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Import Csv Files Project | Import Csv Files | <= 1.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/adc1d752-331e-44af-b5dc-b463d56c2cb4ExploitThird Party Advisory
- https://wpscan.com/vulnerability/adc1d752-331e-44af-b5dc-b463d56c2cb4ExploitThird Party Advisory
FAQ
What is CVE-2022-2146?
CVE-2022-2146 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resu...
How severe is CVE-2022-2146?
CVE-2022-2146 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2146?
Check the references section above for vendor advisories and patch information. Affected products include: Import Csv Files Project Import Csv Files.