Import WP – Export and Import CSV and XML files to WordPress < 2.14.23 - Unauthenticated Information Exposure
medium
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 2.14.23. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.14.23
- Fixed in:
- 2.14.23
- Disclosed:
- Aug 14, 2026
CVE-2026-14925 on NVD →
Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.14.18
unknown
[en] The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.17 via the import/export functionality and a lack of .htaccess protection. This makes it possible for unauthenticated attackers to extract...
- Affected:
- up to 2.14.18
- Fixed in:
- 2.14.18
- Disclosed:
- Nov 21, 2025
CVE-2025-12894 on NVD →
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure
medium
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.17 via the import/export functionality and a lack of .htaccess protection. This makes it possible for unauthenticated attackers to extract sens...
- CVSS:
- 5.3
- Affected:
- up to 2.14.17
- Fixed in:
- 2.14.18
- Disclosed:
- Nov 20, 2025
CVE-2025-12894 on NVD →
Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.14.17
unknown
[en] The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugin's REST API endpoint accepting arbitrary absolute file paths without proper validation in the 'attach_file()' function w...
- Affected:
- up to 2.14.17
- Fixed in:
- 2.14.17
- Disclosed:
- Nov 1, 2025
CVE-2025-12137 on NVD →
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.16 - Authenticated (Admin+) Arbitrary File Read
medium
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugin's REST API endpoint accepting arbitrary absolute file paths without proper validation in the 'attach_file()' function when h...
- CVSS:
- 4.9
- Affected:
- up to 2.14.16
- Fixed in:
- 2.14.17
- Disclosed:
- Oct 31, 2025
CVE-2025-12137 on NVD →
Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.14.6
unknown
[en] The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-...
- Affected:
- up to 2.14.6
- Fixed in:
- 2.14.6
- Disclosed:
- Jan 25, 2025
CVE-2024-13562 on NVD →
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory
high
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-conte...
- CVSS:
- 7.5
- Affected:
- up to 2.14.5
- Fixed in:
- 2.14.6
- Disclosed:
- Jan 24, 2025
CVE-2024-13562 on NVD →
Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.13.1
unknown
[en] The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.
- Affected:
- up to 2.13.1
- Fixed in:
- 2.13.1
- Disclosed:
- Apr 24, 2024
CVE-2023-7253 on NVD →
Import WP – Export and Import CSV and XML files to WordPress <= 2.13.0 - Authenticated (Admin+) Server-Side Request Forgery
medium
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.13.0 via the /wp-json/iwp/v1/importer/$IMPORTERID/upload REST API endpoint. This makes it possible for authenticated attackers, with administrator-le...
- CVSS:
- 5.5
- Affected:
- up to 2.13.0
- Fixed in:
- 2.13.1
- Disclosed:
- Apr 3, 2024
CVE-2023-7253 on NVD →
Import WP – Export and Import CSV and XML files to WordPress [jc-importer] < 2.4.6
unknown
[en] The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.6
- Disclosed:
- May 2, 2022
CVE-2022-1273 on NVD →
Import WP – Import and Export WordPress data to XML or CSV files <= 2.4.5 - Authenticated Arbitrary File Upload
high
The Import WP – Import and Export WordPress data to XML or CSV files plugin for WordPress is vulnerable to arbitrary file upload via high level authenticated users in versions up to, and including, 2.4.5.
- CVSS:
- 7.2
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.6
- Disclosed:
- Apr 11, 2022
CVE-2022-1273 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database