CVE-2015-10125: import all pages\, post types\, products\, orders\, and users as xml \& csv vulnerability
CVE-2015-10125: medium vulnerability affecting import all pages\, post types\, products\, orders\, and users as xml \& csv. Check CVSS, KEV status.
- CVSS
- 4.3 MEDIUM
- EPSS
- 28.58%
- Known exploited
- not in KEV
- Product
- import all pages\, post types\, products\, orders\, and users as xml \& csv
What is known
A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifier of the patch is 13c30af721d3f989caac72dd0f56cf0dc40fad7e. It is recommended to upgrade the affected component. The identifier VDB-241317 was assigned to this vulnerability.
Business impact
Successful exploitation of CVE-2015-10125, a medium vulnerability (CVSS 4.3) affecting import all pages\, post types\, products\, orders\, and users as xml \& csv, may affect the confidentiality, integrity or availability of the vulnerable environment. The exact impact depends on the installed version, exposed interfaces and deployment configuration.
Recommended administrator action
Confirm whether import all pages\, post types\, products\, orders\, and users as xml \& csv is present and compare installed versions with the vendor advisory and NVD record. Apply the vendor patch or documented mitigation; until remediation is complete, reduce exposure of affected interfaces, review relevant logs and monitor for indicators of exploitation. DataHouse can support version verification, managed patching, network exposure reduction, log review and backup validation for dedicated, cloud and colocated environments.