CVE-2024-13562
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-13562 is a newly disclosed vulnerability affecting the Import WP – Export and Import CSV and XML files to WordPress plugin. In its latest versions up to 2.14.5, the plugin exposes sensitive information due to an issue in the uploads directory. This vulnerability allows unauthenticated attackers to extract sensitive data, including imported user data and local files, stored insecurely in the /wp-content/uploads/ directory. The vulnerability poses a significant risk to WordPress sites using the plugin, as it enables potential data breaches and unauthorized access to sensitive information. Immediate action is recommended, including updating the plugin or disabling it until a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Import WP