CVE-2023-7082
HIGHDescription
The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessible directory without sufficiently validating the extracted file type. This may allows high privilege users such as administrator to upload an executable file type leading to remote code execution.
Is your site exposed to CVE-2023-7082?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| soflyy | export_any_wordpress_data_to_xml\/csv |
References
Frequently Asked Questions
What is CVE-2023-7082? +
How severe is CVE-2023-7082? +
What products are affected by CVE-2023-7082? +
How do I check if I'm vulnerable to CVE-2023-7082? +
Related Vulnerabilities
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and …
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …
The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege …
The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions up …
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, …
The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. …