CVE-2022-3677: Addonspress Advanced Import

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks

Affected products

  • Addonspress Advanced Import: before 1.3.8 (fixed in 1.3.8)

Published 2022-12-05. Last modified 2026-06-17.