Description
WordPress Plugin ImportWP-Import any XML or CSV File into WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete specified posts. WordPress Plugin ImportWP-Import any XML or CSV File into WordPress version 1.1.5 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin GiveWP-Donation and Fundraising Platform Multiple Vulnerabilities (2.21.2)
MySQL CVE-2022-21372 Vulnerability (CVE-2022-21372)
WordPress Plugin MAZ Loader-Preloader Builder for WordPress SQL Injection (1.3.2)
Oracle HTTP Server CVE-2006-0435 Vulnerability (CVE-2006-0435)
WordPress Plugin Woocommerce CSV importer Arbitrary File Deletion (3.3.6)