HIGH

CVE-2022-0236

CVSS v3

7.5

HIGH

EPSS Score

37.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

Technical details

Published
1/18/2022

Frequently asked questions

What is CVE-2022-0236?

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

Is CVE-2022-0236 actively exploited?

Active exploitation of CVE-2022-0236 has not been confirmed. The EPSS score is 37.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-0236?

CVE-2022-0236 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2022-0236 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.