The plugin “Import any XML or CSV File to WordPress” for WordPress can be hacked by allowing any type of files to be uploaded without any validation. This can be done by attackers who have admin-level access or higher, which can lead to the execution of remote code on the server of the affected site.