What the vulnerability does
01Description
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
Explanation of Vulnerability in Simple Terms
An authenticated administrator can read, modify, or delete arbitrary files on the WordPress site through the import functionality. The plugin does not properly validate or restrict file access during XML/CSV import operations. An attacker with admin privileges can exploit this to access sensitive data, modify site files, or disrupt site availability.
What an attacker can do
Read, modify, or delete arbitrary files on the WordPress installation.
Potential impact on your site
A compromised admin account can be used to access sensitive files, alter site code, or take the site offline.
Conditions required to exploit
Attacker must have administrator-level access to WordPress.
Key dates
External resources