Extension WordPress
Vulnérabilités WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
Cette page rassemble les failles publiées pour WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
23 fiches
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets <= 4.0.1 – Authenticated (Administrator+) SQL Injection
The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.1 due to insufficient escaping on the user…
*-4.0.1
4.1.0
26/06/2026
WP All Import <= 4.0.0 – Reflected Cross-Site Scripting via 'filepath'
The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due…
*-4.0.0
4.0.1
05/03/2026
Import any XML, CSV or Excel File to WordPress (WP All Import) <= 3.9.6 – Authenticated (Administrator+) Remote Code Execution via Conditional Logic
The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval()…
*-3.9.6
4.0.0
12/11/2025
Import any XML, CSV or Excel File to WordPress <= 3.9.3 – Authenticated (Admin+) Limited Unsafe File Upload
The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This…
*-3.9.3
3.9.4
09/09/2025
Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 – Use of Vulnerable Component (PHPExcel)
Multiple plugins for WordPress utilize a vulnerable dependency (PHPExcel) in various versions. No vulnerabilities have been confirmed exploitable in either plugin, however, an update is still recommended for both.
*-3.8.0
3.9.0
07/04/2025
Import any XML or CSV File to WordPress <= 3.7.3 – Cross-Site Request Forgery to Notice Dismissal
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.7.3. This is due to missing or incorrect nonce validation on several functions.…
*-3.7.3
3.7.4
10/04/2024
Import any XML or CSV File <= 3.7.2 – Authenticated (Admin+) Arbitrary File Upload
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload functionality in all versions up to, and including, 3.7.2 . This…
[*, 3.7.3)
3.7.3
29/12/2023
Import any XML or CSV File to WordPress <= 3.6.8 – Authenticated (Administrator+) Arbitrary File Upload
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to improper file extension validation when uploading files in versions up to, and including, 3.6.8. This makes it possible…
*-3.6.8
3.6.9
17/10/2022
Import any XML or CSV File to WordPress <= 3.6.8 – Authenticated (Administrator+) Arbitrary File Upload via Path Traversal
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file path validation in uploaded zip archives in versions up to, and including, 3.6.8. This makes it…
*-3.6.8
3.6.9
17/10/2022
WP All Import <= 3.6.7 – Admin+ Arbitrary File Upload
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an…
*-3.6.7
3.6.8
01/07/2022
Import any XML or CSV File to WordPress <= 3.6.7 – Admin+ Malicious File Upload
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level…
*-3.6.7
3.6.8
30/06/2022
WP All Import <= 3.6.7 – Authenticated (Administrator+) Arbitrary Code Execution
The WP All Import plugin for WordPress is vulnerable to arbitrary code execution in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator-level permissions and above, to execute arbitrary code.
*-3.6.7
3.6.8
28/06/2022
Import any XML or CSV File to WordPress <= 3.6.6 – Reflected Cross-Site Scripting
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg| without appropriate escaping on the URL in versions up to, and including, 3.6.6. This…
*-3.6.6
3.6.7
02/06/2022
Import any XML or CSV File to WordPress <= 3.6.2 – Authenticated Stored Cross-Site Scripting
The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks…
[*, 3.6.3)
3.6.3
02/11/2021
Import any XML or CSV File to WordPress <= 3.2.4 – Missing Authorization and Cross-Site Request Forgery Checks
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.2.4 due to missing capability and nonce checks on various functions.
*-3.2.4
3.2.5
19/02/2020
Import any XML or CSV File to WordPress <= 3.2.4 – SQL Injection
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and…
*-3.2.4
3.2.5
19/02/2020
Import any XML or CSV File to WordPress <= 3.2.3 & PRO < 4.1.1 – Missing Authorization Checks
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
[*, 3.2.4)
3.2.4
20/08/2019
WP All Import <= 3.4.6 – Cross-Site Scripting
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
[*, 3.4.7)
3.4.7
08/03/2018
WP All Import <= 3.4.5 – Cross-Site Scripting
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
[*, 3.4.6)
3.4.6
08/03/2018
Import any XML or CSV File to WordPress <= 3.4.6 – Cross-Site Scripting
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
[*, 3.4.7)
3.4.7
07/03/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.