Extension WordPress
Vulnérabilités Import WP – Export and Import CSV and XML files to WordPress
Cette page rassemble les failles publiées pour Import WP – Export and Import CSV and XML files to WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Import WP – Export and Import CSV and XML files to WordPress
5 fiches
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.17 – Unauthenticated Information Exposure
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.17 via the import/export functionality and a lack of…
*-2.14.17
2.14.18
20/11/2025
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.16 – Authenticated (Admin+) Arbitrary File Read
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugin's REST API…
*-2.14.16
2.14.17
31/10/2025
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.5 – Unauthenticated Sensitive Information Exposure Through Unprotected Directory
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads directory. This makes it possible…
*-2.14.5
2.14.6
24/01/2025
Import WP – Export and Import CSV and XML files to WordPress <= 2.13.0 – Authenticated (Admin+) Server-Side Request Forgery
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.13.0 via the /wp-json/iwp/v1/importer/$IMPORTERID/upload REST API endpoint. This makes…
*-2.13.0
2.13.1
03/04/2024
Import WP – Import and Export WordPress data to XML or CSV files <= 2.4.5 – Authenticated Arbitrary File Upload
The Import WP – Import and Export WordPress data to XML or CSV files plugin for WordPress is vulnerable to arbitrary file upload via high level authenticated users in versions up to, and including, 2.4.5.
*-2.4.5
2.4.6
11/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.