WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath'
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
Minimum safe version
4.0.1
Update to 4.0.1 or later to address 27 fixable vulnerabilities
CVE-2025-12733
CVE-2025-10001
Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 - Use of Vulnerable Component (PHPExcel)
WordPress WP All Import Plugin <= 3.7.9 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2024-31939
CVE-2023-7082
WP All Import < 3.6.5 - Reflected Cross-Site Scripting
Import any XML or CSV File to WordPress <= 3.2.4 - Missing Authorization and Cross-Site Request Forgery Checks
Import any XML or CSV File to WordPress <= 3.2.4 - SQL Injection
Import any XML or CSV File to WordPress <= 3.6.6 - Reflected Cross-Site Scripting
WordPress Import any XML or CSV File to WordPress Plugin <= 3.6.8 is vulnerable to Directory Traversal
WordPress Import any XML or CSV File to WordPress Plugin <= 3.6.8 is vulnerable to Arbitrary File Upload
CVE-2022-36386
CVE-2022-2268
CVE-2022-1565
WordPress WP All Import Plugin <= 3.2.4 - Multiple Vulnerabilities
WordPress WP All Import Plugin <= 3.2.3 - Remote Code Execution
WordPress Import any XML or CSV File to WordPress plugin <=3.4.5 - Cross-Site Scripting (XSS) vulnerability
WordPress Import any XML or CSV File to WordPress plugin <=3.4.6 - Cross-Site Scripting (XSS) vulnerability
WordPress Import any XML or CSV File to WordPress plugin <=3.4.5 - Cross-Site Scripting (XSS) vulnerability
CVE-2018-16259
CVE-2018-16258
CVE-2018-16256
CVE-2018-16254
CVE-2018-16255
CVE-2018-16257
CVE-2018-20978
CVE-2015-9330
CVE-2015-9329
CVE-2017-18567
CVE-2015-9331
CVE-2021-24714