Unrated severityNVD Advisory· Published Dec 5, 2022· Updated Apr 24, 2025
Advanced Import < 1.3.8 - Arbitrary Plugin Installation & Activation via CSRF
CVE-2022-3677
Description
The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/Advanced Importdescription
- Range: <1.3.8
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/5a7c6367-a3e6-4411-8865-2a9dbc9f1450mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.