The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/ directory which can contain information like imported or local user data and files.
CVE ID: CVE-2024-13562
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
Vendor: jcollings
Product: Import WP – Export and Import CSV and XML files to WordPress
EPSS Score: 0.09% (probability of being exploited)
EPSS Percentile: 39.35% (scored less or equal to compared to others)
EPSS Date: 2025-02-25 (when was this score calculated)