The Import any XML or CSV File to WordPress plugin for WordPress has a security vulnerability. It affects versions up to 3.2.4. An attacker with administrative capabilities can use this vulnerability to gain access to sensitive information from the database. This happens when there is not enough security to prevent the user-supplied parameter from being used in an unsafe way.