plugin

Wp All Import Pro Vulnerabilities

18 known security issues reported for the Wp All Import Pro WordPress plugin. Most recent disclosed Feb 7, 2025.

5 high 5 medium

Running Wp All Import Pro on your site? Check whether your installed version is affected.

Scan your site free

WP All Import Pro <= 4.9.7 - Cross-Site Request Forgery to Imported Content Deletion

medium

The WP All Import Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.7. This is due to missing nonce validation on the delete_and_edit function. This makes it possible for unauthenticated attackers to delete imported content (posts, comments, users, etc.) via...

CVSS:
4.3
Affected:
up to 4.9.7
Fixed in:
4.9.8
Disclosed:
Feb 7, 2025

CVE-2024-9661 on NVD →

WP All Import Pro <= 4.9.7 - Authenticated (Administrator+) PHP Object Injection via Import File

high

The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP cha...

CVSS:
7.2
Affected:
up to 4.9.7
Fixed in:
4.9.8
Disclosed:
Feb 7, 2025

CVE-2024-9664 on NVD →

WP All Import Pro <= 4.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload

medium

The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level acce...

CVSS:
5.5
Affected:
up to 4.9.7
Fixed in:
4.9.8
Disclosed:
Jan 18, 2025

CVE-2024-8722 on NVD →

WP All Import Pro [wp-all-import-pro] < 4.9.4

unknown

[en] The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests...

Affected:
up to 4.9.4
Fixed in:
4.9.4
Disclosed:
Dec 17, 2024

CVE-2024-9624 on NVD →

WP All Import Pro <= 4.9.3 - Authenticated (Administrator+) Server-Side Request Forgery via File Import

high

The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to ar...

CVSS:
7.6
Affected:
up to 4.9.3
Fixed in:
4.9.4
Disclosed:
Dec 16, 2024

CVE-2024-9624 on NVD →

All Import Pro Plugin < 4.1.2 - SQL injection

high

The All Import Pro Plugin for WordPress is vulnerable to blind SQL Injection via the unknown parameter in versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers (co...

CVSS:
8.8
Affected:
up to 4.1.2
Fixed in:
4.1.2
Disclosed:
Mar 19, 2020

WP All Import Pro [wp-all-import-pro] < 4.1.2

unknown

The All Import Pro Plugin for WordPress is vulnerable to blind SQL Injection via the unknown parameter in versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers (co...

Affected:
up to 4.1.2
Fixed in:
4.1.2
Disclosed:
Mar 19, 2020

Import any XML or CSV File to WordPress <= 3.2.4 - SQL Injection

high

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentic...

CVSS:
7.2
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Feb 19, 2020

Import any XML or CSV File to WordPress <= 3.2.4 - Missing Authorization and Cross-Site Request Forgery Checks

medium

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.2.4 due to missing capability and nonce checks on various functions.

CVSS:
6.3
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Feb 19, 2020

WP All Import Pro < 4.1.1 - Reflected Cross Site Scripting

medium

The WP All Import Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

CVSS:
6.1
Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Feb 19, 2020

WP All Import Pro [wp-all-import-pro] < 4.1.1

unknown

The WP All Import Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Feb 19, 2020

Import any XML or CSV File to WordPress <= 3.2.3 & PRO < 4.1.1 - Missing Authorization Checks

high

The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.

CVSS:
7.5
Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Aug 20, 2019

CVE-2015-9331 on NVD →

Import any XML or CSV File to WordPress <= 3.2.4 - Reflected Cross-Site Scripting

medium

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Feb 26, 2015

CVE-2015-9329 on NVD →

WP All Import Pro [wp-all-import-pro] < 4.1.2

unknown

Multiple issues were fixed, such as Authenticated SQL Injection, Authenticated Reflected XSS and Unauthorised access to some methods.

Affected:
up to 4.1.2
Fixed in:
4.1.2

WP All Import Pro [wp-all-import-pro] < 4.1.1

unknown

WP All Import does not properly verify that a user has permission to execute functions. Coupled with an interesting method that allows arbitrary functions in specific objects to be called allows this to be leveraged in many ways.

Affected:
up to 4.1.1
Fixed in:
4.1.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database