Extension WordPress

Vulnérabilités WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel, page 2

Cette page rassemble les failles publiées pour WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel, leurs plages de versions affectées et les correctifs signalés dans la base locale.

27Vulnérabilités
0Critiques
27Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

27 fiches

Vulnérabilité Moyenne · 6,3
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

Easy Drag And drop All Import : WP Ultimate CSV Importer < 6.4.1 – Missing Authorization Checks

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions like upload_function(), display_log(), download_log(), display_csv_values(), etc… in versions up to 6.4.1. This makes it possible for…

Versions affectées

[*, 6.4.1)

Correctif

6.4.1

Publication

12/01/2022

Vulnérabilité Moyenne · 6,1
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

Import Export All WordPress Images, Users & Post Types <= 3.8.7 – Reflected Cross-Site Scripting

The Import Export All WordPress Images, Users & Post Types plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alertmsg’ parameter in versions up to, and including, 3.8.7 due to insufficient input sanitization and output escaping.…

Versions affectées

[*, 3.8.8)

Correctif

3.8.8

Publication

27/01/2018

CVE-2015-10125 Moyenne · 4,3
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

Import CSV or XML Datafeed With Ease <= 3.7.2 – Cross-Site Request Forgery

The Import CSV or XML Datafeed With Ease plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.7.2. This is due to missing or incorrect nonce validation on several functions. This…

Versions affectées

*-3.7.2

Correctif

3.7.3

Publication

05/05/2015

Vulnérabilité Élevée · 7,5
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

WP Ultimate CSV Importer <= 3.7 – Arbitrary File Read

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the templates/readfile.php file in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.7

Correctif

3.7.1

Publication

27/04/2015

Vulnérabilité Élevée · 7,5
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

Ultimate CSV Importer < 3.6.75 – Information Disclosure

The Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.74 via the modules/export/templates/export.php file. This can allow unauthenticated attackers to extract sensitive data including emails, passwords and usernames.

Versions affectées

[*, 3.6.75)

Correctif

3.6.75

Publication

22/02/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités