Key Information Vulnerability Description Vulnerability Type: Unauthenticated Arbitrary File Upload Affected Plugin: AIT CSV Import / Export <= 3.0.3 Discovery Date: November 12, 2020 HTTP Request: GET request to Proof of Concept (PoC) Plugin Content Example: Affected Plugin Plugin Name: all-csv-import-export Fix Status: No known fix available Reference Links AIT Themes Club Additional Information Original Researcher: Ryan of WPScan Verification Status: Verified WPVDB ID: 36e699a4-91f2-428d-ba14-26038fbfeaea Timeline Public Disclosure: 2020-11-13 Added Date: 2020-11-13 Last Updated: 2020-11-14