CVE-2024-13562

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 25, 2025
Updated: Feb 4, 2025
CWE ID 200

Summary

CVE-2024-13562 is a newly disclosed vulnerability affecting the Import WP – Export and Import CSV and XML files to WordPress plugin. In its latest versions up to 2.14.5, the plugin exposes sensitive information due to an issue in the uploads directory. This vulnerability allows unauthenticated attackers to extract sensitive data, including imported user data and local files, stored insecurely in the /wp-content/uploads/ directory. The vulnerability poses a significant risk to WordPress sites using the plugin, as it enables potential data breaches and unauthorized access to sensitive information. Immediate action is recommended, including updating the plugin or disabling it until a patch is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share