Input validation vulnerability in Import any XML or CSV File to WordPress PRO 4.1.2

The All Import Pro Plugin for WordPress is vulnerable to a security issue called blind SQL Injection. This issue affects versions up to 4.1.1 of the plugin. The problem is that the plugin does not properly protect the user input, and when the plugin tries to run a query it does not do enough to prepare for the user input. This makes it possible for someone with an account of Contributor level or higher to add additional queries to the existing ones, which could allow them to access sensitive information from the database.

Detected in:

Import any XML or CSV File to WordPress PRO fixed vulnerable versions: >= * < 4.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.