Vulnerability Description
The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Addonspress | Advanced Import | < 1.3.8 |
References
- https://wpscan.com/vulnerability/5a7c6367-a3e6-4411-8865-2a9dbc9f1450ExploitThird Party Advisory
- https://wpscan.com/vulnerability/5a7c6367-a3e6-4411-8865-2a9dbc9f1450ExploitThird Party Advisory
FAQ
What is CVE-2022-3677?
CVE-2022-3677 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from ...
How severe is CVE-2022-3677?
CVE-2022-3677 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3677?
Check the references section above for vendor advisories and patch information. Affected products include: Addonspress Advanced Import.