plugin

College Publisher Import Vulnerabilities

1 known security issue reported for the College Publisher Import WordPress plugin. Most recent disclosed Apr 11, 2021.

1 high

Running College Publisher Import on your site? Check whether your installed version is affected.

Scan your site free

College publisher Import <= 0.1 - Arbitrary File Upload

high

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

CVSS:
7.2
Affected:
up to 0.1
Fix:
No patched version reported
Disclosed:
Apr 11, 2021

CVE-2021-24254 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database