WP Import – Ultimate CSV XML Importer for WordPress

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Output validation vulnerability in WP Import – Ultimate CSV XML Importer for WordPress 7.33.1

    Fixed

    The WP Import plugin for WordPress is at risk of being attacked by hackers due to a vulnerability in versions up to 7.33.1. This is because of how it handles data from CSV files, which can allow unau...

    Read More
  • Access violation vulnerability in WP Import – Ultimate CSV XML Importer for WordPress 7.33

    Fixed

    The WP Import plugin for WordPress is not secure and could allow unauthorized users to access sensitive information. This is because it lacks proper authorization checks on the showsetting() function...

    Read More
  • Input validation vulnerability in WP Import – Ultimate CSV XML Importer for WordPress 7.28

    Fixed

    The WP Import plugin for WordPress has a security vulnerability that allows attackers to run their own code on a website. This can happen in all versions up to version 7.28. The issue is caused by a ...

    Read More
  • Access violation vulnerability in WP Import – Ultimate CSV XML Importer for WordPress 7.27

    Fixed

    The WP Import plugin for WordPress has a security vulnerability that allows unauthorized users to delete important files from the server. This can lead to serious consequences, such as allowing attac...

    Read More
  • Access violation vulnerability in WP Import – Ultimate CSV XML Importer for WordPress 7.27

    Fixed

    The WP Import plugin for WordPress has a security issue that could allow unauthorized people to access private data. This is because the plugin does not have a way to check if someone has the proper ...

    Read More
  • Input validation vulnerability in Import Export Suite for CSV and XML Datafeed 7.19

    Fixed

    The Import Export Suite for CSV and XML Datafeed plugin for WordPress has a problem that allows anyone with Subscriber-level access or higher to upload any type of file to the website's server. This ...

    Read More
  • Access violation vulnerability in Import Export Suite for CSV and XML Datafeed 7.19

    Fixed

    A plugin called Import Export Suite for CSV and XML Datafeed in WordPress has a security issue. This could allow someone with access to the plugin and a certain level of permissions to delete any fil...

    Read More
  • Input validation vulnerability in Import CSV or XML Datafeed With Ease 3.7.2

    Fixed

    The plugin called "Import CSV or XML Datafeed With Ease" for WordPress has a security issue. It can be hacked by people who are not logged in by tricking the site administrator into clicking on a lin...

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 7.9.8

    Fixed

    The WordPress Ultimate CSV Importer plugin, which is used to import files into WordPress websites, has a security vulnerability in versions up to and including 7.9.8. This vulnerability allows anyone...

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 7.9.8

    Fixed

    The WP Ultimate CSV Importer plugin for WordPress is vulnerable to a security issue that could allow attackers with certain permissions to create a file on the server and run code on it. This issue a...

    Read More
  • Access violation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 7.9.8

    Fixed

    The WP Ultimate CSV Importer plugin for WordPress is vulnerable to an issue that could allow unauthorized users to view certain sensitive files. This issue affects versions of the plugin up to and in...

    Read More
  • Access violation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 7.9.8

    Fixed

    The WordPress Ultimate CSV Importer plugin is vulnerable to a security issue in versions up to, and including, 7.9.8. This flaw could allow attackers, who have at least minimal permissions like an au...

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 6.4.0

    Fixed

    The WP Ultimate CSV Importer plugin for WordPress has a vulnerability which puts the affected website at risk. Subscriber-level attackers can upload any type of file on the server, which could potent...

    Read More
  • Access violation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 6.5.7

    Fixed

    The WP Ultimate CSV Importer plugin

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 5.6

    Fixed

    The wp-ultimate-csv-importer plugin

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 3.8.1

    Fixed

    The wp-ultimate-csv-importer plugin is a program used to help power WordPress websites. It had a security vulnerability in versions before 3.8.1 that allowed hackers to access the website and make cha...

    Read More
  • Access violation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 3.6.75

    Fixed

    The Ultimate CSV Importer plugin for WordPress is not secure in versions 3.6.74 and below. This vulnerability can allow people outside of the website to access sensitive data, such as emails, passwor...

    Read More
  • Access violation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 6.4.1

    Fixed

    The Import all XML, CSV & TXT into WordPress plugin for WordPress has a security flaw that could let attackers delete important information from the website. The flaw exists in versions of the pl...

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 6.4.3

    Fixed

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 3.8.8

    Fixed

    The Import Export All WordPress Images, Users & Post Types plugin for WordPress is vulnerable to a security issue. If you have versions up to and including 3.8.7 of this plugin installed, attacke...

    Read More
  • Access violation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 6.4.1

    Fixed

    The WP Ultimate CSV Importer plugin for WordPress is vulnerable to security issues. In versions up to 6.4.1, attackers with minimal permission (like subscribers) can do unauthorized actions and view ...

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 6.5.2

    Fixed

    The WordPress plugin Import Export All WordPress Images

    Read More
  • Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 6.5.7

    Fixed

    The WP Ultimate CSV Importer plugin for WordPress has a security issue that could let someone with administrator-level access to the website view or change sensitive information from the database. Thi...

    Read More
  • Authentication vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 3.7

    Fixed

    The WP Ultimate CSV Importer plugin for WordPress has a security vulnerability that allows unauthenticated attackers to access any file that PHP has access to. This vulnerability exists in all versio...

    Read More