Extension WordPress

Vulnérabilités WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

Cette page rassemble les failles publiées pour WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel, leurs plages de versions affectées et les correctifs signalés dans la base locale.

27Vulnérabilités
0Critiques
27Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

27 fiches

CVE-2026-13353 Élevée · 8,8
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 8.0.1 – Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is…

Versions affectées

*-8.0.1

Correctif

8.1

Publication

10/07/2026

CVE-2026-1317 Moyenne · 6,5
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 – Authenticated (Subscriber+) SQL Injection via File Name

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.37. This is due to insufficient escaping on the `file_name` parameter which is…

Versions affectées

*-7.37

Correctif

7.38

Publication

17/02/2026

CVE-2025-14627 Moyenne · 6,4
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Import – Ultimate CSV XML Importer for WordPress <= 7.35 – Authenticated (Contributor+) Server-Side Request Forgery via Bitly Shortlink Bypass

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after…

Versions affectées

*-7.35

Correctif

7.36

Publication

01/01/2026

CVE-2025-13145 Élevée · 7,2
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 – Authenticated (Administrator+) PHP Object Injection via CSV Import

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.33.1. This is due to deserialization of untrusted data supplied via CSV…

Versions affectées

*-7.33.1

Correctif

7.34

Publication

18/11/2025

CVE-2025-12732 Moyenne · 4,3
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Import – Ultimate CSV XML Importer for WordPress <= 7.33 – Missing Authorization to Authenticated (Author+) Sensitive Information Exposure

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including,…

Versions affectées

*-7.33

Correctif

7.33.1

Publication

11/11/2025

CVE-2025-10057 Élevée · 8,8
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Import – Ultimate CSV XML Importer for WordPress 7.20 – 7.28 – Authenticated (Subscriber+) Remote Code Execution via Code Injection

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code…

Versions affectées

7.20-7.28

Correctif

7.29

Publication

16/09/2025

CVE-2025-10058 Élevée · 8,1
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Import – Ultimate CSV XML Importer for WordPress <= 7.27 – Authenticated (Subscriber+) Arbitrary File Deletion

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27. This…

Versions affectées

*-7.27

Correctif

7.28

Publication

16/09/2025

CVE-2025-10040 Élevée · 7,7
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Import – Ultimate CSV XML Importer for WordPress <= 7.27 – Missing Authorization to Authenticated (Subscriber+) FTP/SFTP Credential Exposure

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ftp_details' AJAX action in all versions up to, and including,…

Versions affectées

*-7.27

Correctif

7.28

Publication

09/09/2025

CVE-2025-2008 Élevée · 8,8
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

Import Export Suite for CSV and XML Datafeed <= 7.19 – Authenticated (Subscriber+) Arbitrary File Upload

The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import_single_post_as_csv() function in all versions up to, and including, 7.19. This makes…

Versions affectées

*-7.19, 7.20

Correctif

7.19.1, 7.20.1

Publication

31/03/2025

CVE-2025-2007 Élevée · 8,1
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

Import Export Suite for CSV and XML Datafeed <= 7.19 – Authenticated (Subscriber+) Arbitrary File Deletion

The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteImage() function in all versions up to, and including, 7.19. This makes…

Versions affectées

*-7.19, 7.20

Correctif

7.19.1, 7.20.1

Publication

25/03/2025

CVE-2023-4142 Élevée · 8,0
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 7.9.8 – Authenticated (Author+) Remote Code Execution

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously…

Versions affectées

*-7.9.8

Correctif

7.9.9

Publication

03/08/2023

CVE-2023-4141 Élevée · 8,0
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 7.9.8 – Authenticated (Author+) PHP File Creation to Remote Code Execution

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously…

Versions affectées

*-7.9.8

Correctif

7.9.9

Publication

03/08/2023

CVE-2023-4139 Élevée · 7,5
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 7.9.8 – Sensitive Information Exposure via Directory Listing

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated…

Versions affectées

*-7.9.8

Correctif

7.9.9

Publication

03/08/2023

CVE-2023-4140 Moyenne · 6,6
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 7.9.8 – Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions…

Versions affectées

*-7.9.8

Correctif

7.9.9

Publication

03/08/2023

CVE-2022-3244 Moyenne · 5,4
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 6.5.7 – Missing Authorization

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on some of its functions in versions up to, and including, 6.5.7. This makes it possible for authenticated attackers,…

Versions affectées

*-6.5.7

Correctif

6.5.8

Publication

20/09/2022

CVE-2022-3243 Élevée · 7,2
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 6.5.7 – Authenticated (Administrator+) SQL Injection

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

Versions affectées

*-6.5.7

Correctif

6.5.8

Publication

20/09/2022

CVE-2022-0360 Moyenne · 4,8
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 6.4.2 – Admin+ Stored Cross-Site Scripting

The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and…

Versions affectées

[*, 6.4.3)

Correctif

6.4.3

Publication

26/01/2022

Vulnérabilité Élevée · 7,1
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

Import all XML, CSV & TXT into WordPress < 6.4.2 – Missing Authorization

The Import all XML, CSV & TXT into WordPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the disable_main_mode function in versions up to, and including, 6.4.1. This makes it possible…

Versions affectées

*-6.4.1

Correctif

6.4.2

Publication

17/01/2022

Vulnérabilité Élevée · 8,8
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 6.4.0 – Arbitrary File Upload

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip_upload AJAX call in versions up to, and including, 6.4.0. This makes it possible for subscriber-level…

Versions affectées

*-6.4.0

Correctif

6.4.1

Publication

12/01/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités