Vulnerabilities > Vjinfotech > WP Import Export

DATE CVE VULNERABILITY TITLE RISK
2022-01-18 CVE-2022-0236 Missing Authorization vulnerability in Vjinfotech WP Import Export and WP Import Export Lite
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file.
network
low complexity
vjinfotech CWE-862
5.0