Fiche vulnérabilité
CVE-2022-1273 : faille élevée importwp import wp (CVSS 7.2)
Description
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE
En bref
- Sévérité
- Élevée (CVSS 7.2)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 2 mai 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- importwp import wp