The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to a type of security issue known as Reflected Cross-Site Scripting. This means that if a user is tricked into clicking a link, it is possible for unauthenticated attackers to inject web scripts into pages. This security issue affects versions of the plugin up to and including 3.6.6 and is due to the lack of appropriate escaping on the URL.