Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown
CVE-2022-2268
Disclosure Date: July 04, 2022 (last updated February 24, 2025)
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
0
Attacker Value
Unknown
CVE-2022-36386
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
0
Attacker Value
Unknown
CVE-2022-1800
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
0
Attacker Value
Unknown
CVE-2021-24714
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2018-20978
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2015-9331
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
0
Attacker Value
Unknown
CVE-2015-9330
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
0
Attacker Value
Unknown
CVE-2017-18567
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2015-9329
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
0
Attacker Value
Unknown
CVE-2018-16259
Disclosure Date: April 12, 2019 (last updated November 08, 2023)
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
0