Vulnerabilities (CVE)

Filtered by vendor Importwp Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1273 1 Importwp 1 Import Wp 2024-11-21 6.5 MEDIUM 7.2 HIGH
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE