plugin

Jc Importer Vulnerabilities

11 known security issues reported for the Jc Importer WordPress plugin. Most recent disclosed Aug 14, 2026.

2 high 4 medium

Running Jc Importer on your site? Check whether your installed version is affected.

Scan your site free

Import WP – Export and Import CSV and XML files to WordPress < 2.14.23 - Unauthenticated Information Exposure

medium

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 2.14.23. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.14.23
Fixed in:
2.14.23
Disclosed:
Aug 14, 2026

CVE-2026-14925 on NVD →

Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.14.18

unknown

[en] The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.17 via the import/export functionality and a lack of .htaccess protection. This makes it possible for unauthenticated attackers to extract...

Affected:
up to 2.14.18
Fixed in:
2.14.18
Disclosed:
Nov 21, 2025

CVE-2025-12894 on NVD →

Import WP – Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure

medium

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.17 via the import/export functionality and a lack of .htaccess protection. This makes it possible for unauthenticated attackers to extract sens...

CVSS:
5.3
Affected:
up to 2.14.17
Fixed in:
2.14.18
Disclosed:
Nov 20, 2025

CVE-2025-12894 on NVD →

Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.14.17

unknown

[en] The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugin's REST API endpoint accepting arbitrary absolute file paths without proper validation in the 'attach_file()' function w...

Affected:
up to 2.14.17
Fixed in:
2.14.17
Disclosed:
Nov 1, 2025

CVE-2025-12137 on NVD →

Import WP – Export and Import CSV and XML files to WordPress <= 2.14.16 - Authenticated (Admin+) Arbitrary File Read

medium

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugin's REST API endpoint accepting arbitrary absolute file paths without proper validation in the 'attach_file()' function when h...

CVSS:
4.9
Affected:
up to 2.14.16
Fixed in:
2.14.17
Disclosed:
Oct 31, 2025

CVE-2025-12137 on NVD →

Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.14.6

unknown

[en] The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-...

Affected:
up to 2.14.6
Fixed in:
2.14.6
Disclosed:
Jan 25, 2025

CVE-2024-13562 on NVD →

Import WP – Export and Import CSV and XML files to WordPress <= 2.14.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

high

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-conte...

CVSS:
7.5
Affected:
up to 2.14.5
Fixed in:
2.14.6
Disclosed:
Jan 24, 2025

CVE-2024-13562 on NVD →

Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.13.1

unknown

[en] The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

Affected:
up to 2.13.1
Fixed in:
2.13.1
Disclosed:
Apr 24, 2024

CVE-2023-7253 on NVD →

Import WP – Export and Import CSV and XML files to WordPress <= 2.13.0 - Authenticated (Admin+) Server-Side Request Forgery

medium

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.13.0 via the /wp-json/iwp/v1/importer/$IMPORTERID/upload REST API endpoint. This makes it possible for authenticated attackers, with administrator-le...

CVSS:
5.5
Affected:
up to 2.13.0
Fixed in:
2.13.1
Disclosed:
Apr 3, 2024

CVE-2023-7253 on NVD →

Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.4.6

unknown

[en] The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE

Affected:
up to 2.4.6
Fixed in:
2.4.6
Disclosed:
May 2, 2022

CVE-2022-1273 on NVD →

Import WP – Import and Export WordPress data to XML or CSV files <= 2.4.5 - Authenticated Arbitrary File Upload

high

The Import WP – Import and Export WordPress data to XML or CSV files plugin for WordPress is vulnerable to arbitrary file upload via high level authenticated users in versions up to, and including, 2.4.5.

CVSS:
7.2
Affected:
up to 2.4.5
Fixed in:
2.4.6
Disclosed:
Apr 11, 2022

CVE-2022-1273 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database