WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name
WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress
Minimum safe version
7.38
Update to 7.38 or later to address 38 fixable vulnerabilities
CVE-2025-14627
CVE-2025-13145
CVE-2025-12732
CVE-2025-10057
CVE-2025-10058
CVE-2025-10040
Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Upload
Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Deletion
CVE-2015-10125
WP Ultimate CSV Importer <= 3.8.6 - Reflected Cross-Site Scripting (XSS)
WP Ultimate CSV Importer < 6.4.1 - Subscriber+ Arbitrary File Upload
WP Ultimate CSV Importer < 6.4.2 - Subscriber+ Arbitrary Option Deletion
WP Ultimate CSV Importer <= 3.6.74 - Database Table Export
WP Ultimate CSV Importer < 3.7.1 - Directory Traversal
CVE-2023-4141
CVE-2023-4140
CVE-2023-4139
CVE-2023-4142
Ultimate CSV Importer < 3.6.75 - Information Disclosure
WP Ultimate CSV Importer <= 3.7 - Arbitrary File Read
Import Export All WordPress Images, Users & Post Types <= 3.8.7 - Reflected Cross-Site Scripting
WP Ultimate CSV Importer <= 6.4.0 - Arbitrary File Upload
Easy Drag And drop All Import : WP Ultimate CSV Importer < 6.4.1 - Missing Authorization Checks
Import all XML, CSV & TXT into WordPress < 6.4.2 - Missing Authorization
CVE-2022-3244
CVE-2022-3243
WordPress Ultimate CSV Importer Plugin <= 3.7.0 - Directory Traversal
WordPress Ultimate CSV Importer Plugin <= 3.6.74 Information Disclosure
CVE-2022-1977
WordPress Ultimate CSV Importer Plugin <= 3.8.6 - Reflected Cross Site Scripting
WordPress WP Ultimate CSV Importer plugin <= 6.4 - Plugin Settings Update vulnerability
WordPress WP Ultimate CSV Importer plugin <= 6.4 - Arbitrary Media File Deletion vulnerability
WordPress WP Ultimate CSV Importer plugin <= 6.4 - Arbitrary File Upload vulnerability
WordPress WP Ultimate CSV Importer plugin <= 6.4.1 - Arbitrary Option Deletion vulnerability
CVE-2015-9306
CVE-2018-20967
CVE-2022-0360