← Back to CVE List

CVE-2022-3243

Published: 2022-10-17T12:15Z
Last Modified: 2024-11-21T07:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin > MITRE Terms of Use apply – see LICENSE‑MITRE.txt