Extension WordPress

Vulnérabilités Import WP – Export and Import CSV and XML files to WordPress

Cette page rassemble les failles publiées pour Import WP – Export and Import CSV and XML files to WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Import WP – Export and Import CSV and XML files to WordPress

5 fiches

CVE-2025-12894 Moyenne · 5,3
Import WP – Export and Import CSV and XML files to WordPress

Import WP – Export and Import CSV and XML files to WordPress <= 2.14.17 – Unauthenticated Information Exposure

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.17 via the import/export functionality and a lack of…

Versions affectées

*-2.14.17

Correctif

2.14.18

Publication

20/11/2025

CVE-2025-12137 Moyenne · 4,9
Import WP – Export and Import CSV and XML files to WordPress

Import WP – Export and Import CSV and XML files to WordPress <= 2.14.16 – Authenticated (Admin+) Arbitrary File Read

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugin's REST API…

Versions affectées

*-2.14.16

Correctif

2.14.17

Publication

31/10/2025

CVE-2024-13562 Élevée · 7,5
Import WP – Export and Import CSV and XML files to WordPress

Import WP – Export and Import CSV and XML files to WordPress <= 2.14.5 – Unauthenticated Sensitive Information Exposure Through Unprotected Directory

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads directory. This makes it possible…

Versions affectées

*-2.14.5

Correctif

2.14.6

Publication

24/01/2025

CVE-2023-7253 Moyenne · 5,5
Import WP – Export and Import CSV and XML files to WordPress

Import WP – Export and Import CSV and XML files to WordPress <= 2.13.0 – Authenticated (Admin+) Server-Side Request Forgery

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.13.0 via the /wp-json/iwp/v1/importer/$IMPORTERID/upload REST API endpoint. This makes…

Versions affectées

*-2.13.0

Correctif

2.13.1

Publication

03/04/2024

CVE-2022-1273 Élevée · 7,2
Import WP – Export and Import CSV and XML files to WordPress

Import WP – Import and Export WordPress data to XML or CSV files <= 2.4.5 – Authenticated Arbitrary File Upload

The Import WP – Import and Export WordPress data to XML or CSV files plugin for WordPress is vulnerable to arbitrary file upload via high level authenticated users in versions up to, and including, 2.4.5.

Versions affectées

*-2.4.5

Correctif

2.4.6

Publication

11/04/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités