CVE-2022-1977

CVE-2022-1977: WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF

Vendor Unknown
Product Import Export All WordPress Images, Users & Post Types
Weakness CWE-918 · SSRF
Published June 27, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

Key dates

02Disclosure timeline

June 27, 2022 CVE published
August 3, 2024 Record updated