plugin

Tp2Wp Importer Vulnerabilities

1 known security issue reported for the Tp2Wp Importer WordPress plugin. Most recent disclosed Feb 25, 2026.

1 medium

Running Tp2Wp Importer on your site? Check whether your installed version is affected.

Scan your site free

TP2WP Importer <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Watched domains' Textarea

medium

The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping when domains are saved via AJAX and rendered with...

CVSS:
4.4
Affected:
up to 1.1
Fix:
No patched version reported
Disclosed:
Feb 25, 2026

CVE-2026-2489 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database