Vulnerabilities > CVE-2022-0236 - Missing Authorization vulnerability in Vjinfotech WP Import Export Lite
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/qurbat/CVE-2022-0236
- https://github.com/qurbat/CVE-2022-0236
- https://plugins.trac.wordpress.org/changeset/2649762/wp-import-export-lite/trunk/includes/classes/class-wpie-general.php
- https://plugins.trac.wordpress.org/changeset/2649762/wp-import-export-lite/trunk/includes/classes/class-wpie-general.php
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0236
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0236