Description
WordPress Plugin WP Import Export is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin WP Import Export version 3.9.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.9.16 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0236
http://plugins.vjinfotech.com/wordpress-import-export/change-log/
Related Vulnerabilities
Drupal Core 8.x Security Bypass (8.0.0 - 8.1.6)
WordPress Plugin AMP for WP-Accelerated Mobile Pages Multiple Unspecified Vulnerabilities (0.9.72)
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-5045)
WordPress Plugin Human Presence Cross-Site Scripting (2.0.8)
Moodle Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-5153)