CVE-2022-0360
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues
- Affected products
- Wp Ultimate Csv Importer
- Smackcoders Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv
- < 6.4.3
- Fix
- Available
- CVSS 3.1
- 4.8 MEDIUM
- EPSS
- 0.6% (49th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2022-02-28
CVE-2022-0360 at NVD
1 known exploit for CVE-2022-0360
Proof-of-concept code and exploit modules indexed by Sploitus