Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2021-24714

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2018-20978

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2015-9331

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
0
Attacker Value
Unknown

CVE-2015-9330

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
0
Attacker Value
Unknown

CVE-2017-18567

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2015-9329

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
0
Attacker Value
Unknown

CVE-2018-16259

Disclosure Date: April 12, 2019 (last updated November 08, 2023)
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
0
Attacker Value
Unknown

CVE-2018-16257

Disclosure Date: April 12, 2019 (last updated November 08, 2023)
There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
0
Attacker Value
Unknown

CVE-2018-16258

Disclosure Date: April 12, 2019 (last updated November 08, 2023)
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
0
Attacker Value
Unknown

CVE-2018-16254

Disclosure Date: April 12, 2019 (last updated November 08, 2023)
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
0