Input validation vulnerability in Import any XML, CSV or Excel File to WordPress 3.9.6

A plugin called Import any XML, CSV or Excel File to WordPress (WP All Import) for WordPress has a security vulnerability in all versions up to 3.9.6. This is because it uses a function called eval() on input that has not been checked for harmful code. This means that attackers who have access to the plugin (usually administrators) can insert their own PHP code and make it run on the server. This could result in remote code execution, which is a serious issue.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.