CVE-2022-1565
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
- Published
- Jul 18, 2022
- Updated
- Apr 8, 2026
- Assigning CNA
- Wordfence
- Evidence observed
- Mar 29, 2023
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.
Authenticated remote code execution exploit for WordPress WP All Import plugin <= 3.6.7 (CVE-2022-1565). Uploads arbitrary files via insecure file type validation in wp_all_import_get_gz.php.
AkuCyberSec · php · Mar 29, 2023
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.