WP Import Export (Lite) <= 3.9.15 Unauthenticated Sensitive Data Disclosure
Vulnerability Description
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-0236
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Karan Saini (Kloudle Inc.)
References
More from vjinfotech
View All →Affected Vendor
vjinfotech
View all reports →