CVE-2022-1565 EXPLOIT
7.2
HIGH · CVSS 3.1 · EPSS 15.4% (pctl 97)
Patch early
A public exploit exists.
Description
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.
Scoring
| CVSS | 7.2 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 15.4% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-07-18 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| wpallimport | wp all import |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated) | 2023-03-29 |
References
- https://plugins.trac.wordpress.org/changeset/2749264/wp-all-import/trunk?contextall=1&old=2737093&old_path=%2Fwp-all-import%2Ftrunk
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5d281333-d9af-4eb7-bc5c-ea7ceeddac03?source=cve
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1565
- https://plugins.trac.wordpress.org/changeset/2749264/wp-all-import/trunk?contextall=1&old=2737093&old_path=%2Fwp-all-import%2Ftrunk
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5d281333-d9af-4eb7-bc5c-ea7ceeddac03?source=cve
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1565
→ the Explorer · watch your stack · NVD