Access violation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 6.4.1

The Import all XML, CSV & TXT into WordPress plugin for WordPress has a security flaw that could let attackers delete important information from the website. The flaw exists in versions of the plugin up to 6.4.1. Any user who has signed up for an account and has at least “Subscriber-level” permissions could delete any site options. This vulnerability can be easily abused, so it’s important to update the plugin to the latest version as soon as possible.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.