PoC Index

CVE-2022-3243

HIGH 7.2EPSS 1.1%

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.06% chance of exploitation in the next 30 days, 62th percentile
Published
2022-10-17
Updated
2025-05-14

Proof-of-concept exploits (1)

References

Related