Vulnerabilities > CVE-2022-3244 - Missing Authorization vulnerability in Smackcoders Import ALL Pages, Post Types, Products, Orders, and Users AS XML & CSV

047910
CVSS 4.2 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
high complexity
smackcoders
CWE-862

Summary

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce

Vulnerable Configurations

Part Description Count
Application
Smackcoders
1

Common Weakness Enumeration (CWE)