← volver
CVE-2025-4190

CSV Mass Importer <= 1.2 - Admin+ Arbitrary File Upload

CVSS 7.2 HIGHEPSS 0.5%
The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Unknown · CSV Mass Importer

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →