CVE-2022-3243

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
17/10/2022
Last modified:
14/05/2025

Description

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smackcoders:import_all_pages\,_post_types\,_products\,_orders\,_and_users_as_xml_\&_csv:*:*:*:*:wordpress:*:*:* 6.5.8 (excluding)