Medium severity6.5NVD Advisory· Published Dec 5, 2022· Updated Jun 17, 2026
CVE-2022-3677
CVE-2022-3677
Description
The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <1.3.8
- WordPress/Advanced Importdescription
- cpe:2.3:a:addonspress:advanced_import:*:*:*:*:*:wordpress:*:*Range: <1.3.8
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/5a7c6367-a3e6-4411-8865-2a9dbc9f1450nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.