CVE-2022-2268
Last modified
CVE-2022-2268 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Soflyy | Wp All Import | < 3.6.8 |
References
- https://wpscan.com/vulnerability/578093db-a025-4148-8c4b-ec2df31743f7Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/578093db-a025-4148-8c4b-ec2df31743f7Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2268?
How severe is CVE-2022-2268?
How do I fix CVE-2022-2268?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22673This issue was addressed with improved checks. This issue is…7.5
- CVE-2022-22674An out-of-bounds read issue existed that led to the disclosu…5.5
- CVE-2022-22675An out-of-bounds write issue was addressed with improved bou…7.8
- CVE-2022-22676An event handler validation issue in the XPC Services API wa…5.5
- CVE-2022-22677A logic issue in the handling of concurrent media was addres…4.3
- CVE-2022-22679Improper limitation of a pathname to a restricted directory …4.9
- CVE-2022-22680Exposure of sensitive information to an unauthorized actor v…7.5
- CVE-2022-22681Session fixation vulnerability in access control management …7.5
- CVE-2022-22682Improper neutralization of input during web page generation …5.4
- CVE-2022-22683Buffer copy without checking size of input ('Classic Buffer …9.8
- CVE-2022-22684Improper neutralization of special elements used in an OS co…8.8
- CVE-2022-22685Improper limitation of a pathname to a restricted directory …8.1
Are you affected by CVE-2022-2268?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
