Extension WordPress

Vulnérabilités WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Cette page rassemble les failles publiées pour WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets, leurs plages de versions affectées et les correctifs signalés dans la base locale.

23Vulnérabilités
2Critiques
23Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

23 fiches

CVE-2026-57628 Moyenne · 4,9
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets <= 4.0.1 – Authenticated (Administrator+) SQL Injection

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.1 due to insufficient escaping on the user…

Versions affectées

*-4.0.1

Correctif

4.1.0

Publication

26/06/2026

CVE-2025-12733 Élevée · 8,8
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML, CSV or Excel File to WordPress (WP All Import) <= 3.9.6 – Authenticated (Administrator+) Remote Code Execution via Conditional Logic

The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval()…

Versions affectées

*-3.9.6

Correctif

4.0.0

Publication

12/11/2025

CVE-2025-10001 Élevée · 7,2
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML, CSV or Excel File to WordPress <= 3.9.3 – Authenticated (Admin+) Limited Unsafe File Upload

The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This…

Versions affectées

*-3.9.3

Correctif

3.9.4

Publication

09/09/2025

CVE-2014-2054 Faible · 3,7
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 – Use of Vulnerable Component (PHPExcel)

Multiple plugins for WordPress utilize a vulnerable dependency (PHPExcel) in various versions. No vulnerabilities have been confirmed exploitable in either plugin, however, an update is still recommended for both.

Versions affectées

*-3.8.0

Correctif

3.9.0

Publication

07/04/2025

CVE-2024-31939 Informationnelle
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML or CSV File to WordPress <= 3.7.3 – Cross-Site Request Forgery to Notice Dismissal

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.7.3. This is due to missing or incorrect nonce validation on several functions.…

Versions affectées

*-3.7.3

Correctif

3.7.4

Publication

10/04/2024

CVE-2023-7082 Élevée · 7,2
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML or CSV File <= 3.7.2 – Authenticated (Admin+) Arbitrary File Upload

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload functionality in all versions up to, and including, 3.7.2 . This…

Versions affectées

[*, 3.7.3)

Correctif

3.7.3

Publication

29/12/2023

CVE-2022-3418 Moyenne · 6,5
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML or CSV File to WordPress <= 3.6.8 – Authenticated (Administrator+) Arbitrary File Upload

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to improper file extension validation when uploading files in versions up to, and including, 3.6.8. This makes it possible…

Versions affectées

*-3.6.8

Correctif

3.6.9

Publication

17/10/2022

CVE-2022-2711 Moyenne · 6,5
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML or CSV File to WordPress <= 3.6.8 – Authenticated (Administrator+) Arbitrary File Upload via Path Traversal

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file path validation in uploaded zip archives in versions up to, and including, 3.6.8. This makes it…

Versions affectées

*-3.6.8

Correctif

3.6.9

Publication

17/10/2022

CVE-2022-1565 Élevée · 7,2
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML or CSV File to WordPress <= 3.6.7 – Admin+ Malicious File Upload

The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level…

Versions affectées

*-3.6.7

Correctif

3.6.8

Publication

30/06/2022

CVE-2022-36386 Critique · 9,1
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

WP All Import <= 3.6.7 – Authenticated (Administrator+) Arbitrary Code Execution

The WP All Import plugin for WordPress is vulnerable to arbitrary code execution in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator-level permissions and above, to execute arbitrary code.

Versions affectées

*-3.6.7

Correctif

3.6.8

Publication

28/06/2022

Vulnérabilité Moyenne · 6,1
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML or CSV File to WordPress <= 3.6.6 – Reflected Cross-Site Scripting

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg| without appropriate escaping on the URL in versions up to, and including, 3.6.6. This…

Versions affectées

*-3.6.6

Correctif

3.6.7

Publication

02/06/2022

CVE-2021-24714 Moyenne · 4,8
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML or CSV File to WordPress <= 3.6.2 – Authenticated Stored Cross-Site Scripting

The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks…

Versions affectées

[*, 3.6.3)

Correctif

3.6.3

Publication

02/11/2021

Vulnérabilité Moyenne · 6,3
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

Import any XML or CSV File to WordPress <= 3.2.4 – Missing Authorization and Cross-Site Request Forgery Checks

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.2.4 due to missing capability and nonce checks on various functions.

Versions affectées

*-3.2.4

Correctif

3.2.5

Publication

19/02/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités