Description
WordPress Plugin WP Import Export is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin WP Import Export version 3.9.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.9.16 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0236
http://plugins.vjinfotech.com/wordpress-import-export/change-log/
Related Vulnerabilities
WordPress Plugin WP Statistics SQL Injection (13.0.7)
WordPress Plugin SecureMoz Security Audit PHP Object Injection (1.0.5)
WordPress Plugin WP Post to PDF Enhanced Cross-Site Scripting (1.0.5)
Coppermine Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3481)
WordPress Plugin Integration for Contact Form 7 and Zoho Cross-Site Scripting (1.1.7)