High 7.2
2025-02-07< 4.9.8
WP All Import Pro <= 4.9.7 - Authenticated (Administrator+) PHP Object Injection via Import File
Minimum safe version
4.9.8
Update to 4.9.8 or later to address 8 fixable vulnerabilities
WP All Import Pro <= 4.9.7 - Authenticated (Administrator+) PHP Object Injection via Import File
WP All Import Pro <= 4.9.7 - Cross-Site Request Forgery to Imported Content Deletion
WP All Import Pro <= 4.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload
CVE-2024-9624
WP All Import Pro <= 4.1.0 - RCE
WP All Import Pro <= 4.1.1 - Multiple Vulnerabilities
WP All Import Pro < 4.1.1 - Reflected Cross Site Scripting
All Import Pro Plugin < 4.1.2 - SQL injection