Extension WordPress
Vulnérabilités WP All Import Pro
Cette page rassemble les failles publiées pour WP All Import Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP All Import Pro
10 fiches
WP All Import Pro <= 4.9.7 – Cross-Site Request Forgery to Imported Content Deletion
The WP All Import Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.7. This is due to missing nonce validation on the delete_and_edit function. This makes it possible for…
*-4.9.7
4.9.8
07/02/2025
WP All Import Pro <= 4.9.7 – Authenticated (Administrator+) PHP Object Injection via Import File
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers,…
*-4.9.7
4.9.8
07/02/2025
WP All Import Pro <= 4.9.7 – Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload
The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output…
*-4.9.7
4.9.8
18/01/2025
WP All Import Pro <= 4.9.3 – Authenticated (Administrator+) Server-Side Request Forgery via File Import
The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers,…
*-4.9.3
4.9.4
16/12/2024
All Import Pro Plugin < 4.1.2 – SQL injection
The All Import Pro Plugin for WordPress is vulnerable to blind SQL Injection via the unknown parameter in versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
[*, 4.1.2)
4.1.2
19/03/2020
Import any XML or CSV File to WordPress <= 3.2.4 – Missing Authorization and Cross-Site Request Forgery Checks
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.2.4 due to missing capability and nonce checks on various functions.
*-4.1.1
4.1.2
19/02/2020
Import any XML or CSV File to WordPress <= 3.2.4 – SQL Injection
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and…
*-4.1.1
4.1.2
19/02/2020
WP All Import Pro < 4.1.1 – Reflected Cross Site Scripting
The WP All Import Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 4.1.1)
4.1.1
19/02/2020
Import any XML or CSV File to WordPress <= 3.2.3 & PRO < 4.1.1 – Missing Authorization Checks
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
[*, 4.1.1)
4.1.1
20/08/2019
Import any XML or CSV File to WordPress <= 3.2.4 – Reflected Cross-Site Scripting
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.1.1
4.1.2
26/02/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.