WP All Import Pro <= 4.9.7 - Cross-Site Request Forgery to Imported Content Deletion
medium
The WP All Import Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.7. This is due to missing nonce validation on the delete_and_edit function. This makes it possible for unauthenticated attackers to delete imported content (posts, comments, users, etc.) via...
- CVSS:
- 4.3
- Affected:
- up to 4.9.7
- Fixed in:
- 4.9.8
- Disclosed:
- Feb 7, 2025
CVE-2024-9661 on NVD →
WP All Import Pro <= 4.9.7 - Authenticated (Administrator+) PHP Object Injection via Import File
high
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP cha...
- CVSS:
- 7.2
- Affected:
- up to 4.9.7
- Fixed in:
- 4.9.8
- Disclosed:
- Feb 7, 2025
CVE-2024-9664 on NVD →
WP All Import Pro <= 4.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload
medium
The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level acce...
- CVSS:
- 5.5
- Affected:
- up to 4.9.7
- Fixed in:
- 4.9.8
- Disclosed:
- Jan 18, 2025
CVE-2024-8722 on NVD →
WP All Import Pro [wp-all-import-pro] < 4.9.4
unknown
[en] The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests...
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.4
- Disclosed:
- Dec 17, 2024
CVE-2024-9624 on NVD →
WP All Import Pro <= 4.9.3 - Authenticated (Administrator+) Server-Side Request Forgery via File Import
high
The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to ar...
- CVSS:
- 7.6
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.4
- Disclosed:
- Dec 16, 2024
CVE-2024-9624 on NVD →
All Import Pro Plugin < 4.1.2 - SQL injection
high
The All Import Pro Plugin for WordPress is vulnerable to blind SQL Injection via the unknown parameter in versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers (co...
- CVSS:
- 8.8
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
- Disclosed:
- Mar 19, 2020
WP All Import Pro [wp-all-import-pro] < 4.1.2
unknown
The All Import Pro Plugin for WordPress is vulnerable to blind SQL Injection via the unknown parameter in versions up to, and including, 4.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers (co...
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
- Disclosed:
- Mar 19, 2020
Import any XML or CSV File to WordPress <= 3.2.4 - SQL Injection
high
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentic...
- CVSS:
- 7.2
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Feb 19, 2020
Import any XML or CSV File to WordPress <= 3.2.4 - Missing Authorization and Cross-Site Request Forgery Checks
medium
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.2.4 due to missing capability and nonce checks on various functions.
- CVSS:
- 6.3
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Feb 19, 2020
WP All Import Pro < 4.1.1 - Reflected Cross Site Scripting
medium
The WP All Import Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...
- CVSS:
- 6.1
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 19, 2020
WP All Import Pro [wp-all-import-pro] < 4.1.1
unknown
The WP All Import Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 19, 2020
Import any XML or CSV File to WordPress <= 3.2.3 & PRO < 4.1.1 - Missing Authorization Checks
high
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
- CVSS:
- 7.5
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Aug 20, 2019
CVE-2015-9331 on NVD →
Import any XML or CSV File to WordPress <= 3.2.4 - Reflected Cross-Site Scripting
medium
The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Feb 26, 2015
CVE-2015-9329 on NVD →
WP All Import Pro [wp-all-import-pro] < 4.1.2
unknown
Multiple issues were fixed, such as Authenticated SQL Injection, Authenticated Reflected XSS and Unauthorised access to some methods.
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
WP All Import Pro [wp-all-import-pro] < 4.1.1
unknown
WP All Import does not properly verify that a user has permission to execute functions. Coupled with an interesting method that allows arbitrary functions in specific objects to be called allows this to be leveraged in many ways.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
WP All Import Pro [wp-all-import-pro] < 4.9.8
unknown
- Affected:
- up to 4.9.8
- Fixed in:
- 4.9.8
CVE-2024-8722 on NVD →
WP All Import Pro [wp-all-import-pro] < 4.9.8
unknown
- Affected:
- up to 4.9.8
- Fixed in:
- 4.9.8
CVE-2024-9661 on NVD →
WP All Import Pro [wp-all-import-pro] < 4.9.8
unknown
- Affected:
- up to 4.9.8
- Fixed in:
- 4.9.8
CVE-2024-9664 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database