Skip to main content

Vendor/product archive

soflyy / wp_all_import CVEs

Beta · best-effort

19 CVEs tagged to soflyy / wp_all_import2 Critical, 5 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2024-9664

Published Feb 7, 2025

The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3418

Published Nov 7, 2022

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow adminis…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2711

Published Nov 7, 2022

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36386

Published Sep 21, 2022

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2268

Published Jul 4, 2022

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24714

Published Dec 6, 2021

The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9331

Published Aug 20, 2019

The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16259

Published Apr 12, 2019

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP Al…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16258

Published Apr 12, 2019

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Impor…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16257

Published Apr 12, 2019

There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16256

Published Apr 12, 2019

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Imp…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16255

Published Apr 12, 2019

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16254

Published Apr 12, 2019

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0547

Published Mar 9, 2018

Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0546

Published Mar 9, 2018

Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1