Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2022-2268

Disclosure Date: July 04, 2022 (last updated February 24, 2025)
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
Attacker Value
Unknown

CVE-2022-36386

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
Attacker Value
Unknown

CVE-2022-1800

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
Attacker Value
Unknown

CVE-2021-24714

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2018-20978

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2015-9331

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
0
Attacker Value
Unknown

CVE-2015-9330

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
0
Attacker Value
Unknown

CVE-2017-18567

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2015-9329

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
0
Attacker Value
Unknown

CVE-2018-16259

Disclosure Date: April 12, 2019 (last updated November 08, 2023)
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
0