Information leakage vulnerability in Import WP – Export and Import CSV and XML files to WordPress 2.14.17

A plugin for WordPress called “Import WP” has a security issue that affects all versions up to 2.14.17. This issue allows attackers to access sensitive information through the import and export feature, as there is no protection in place to prevent this. This means that attackers who are not logged in can access and extract sensitive data from the plugin’s export folder and import folder.

Detected in:

Import WP – Export and Import CSV and XML files to WordPress fixed vulnerable versions: >= * <= 2.14.17

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.