plugin

Wp Ultimate Csv Importer Vulnerabilities

64 known security issues reported for the Wp Ultimate Csv Importer WordPress plugin. Most recent disclosed Jul 10, 2026.

16 high 11 medium

Running Wp Ultimate Csv Importer on your site? Check whether your installed version is affected.

Scan your site free

WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter

high

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and S...

CVSS:
8.8
Affected:
up to 8.0.1
Fixed in:
8.1
Disclosed:
Jul 10, 2026

CVE-2026-13353 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name

medium

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.37. This is due to insufficient escaping on the `file_name` parameter which is stored in the database during file upload and later used in raw SQL queries without proper sa...

CVSS:
6.5
Affected:
up to 7.37
Fixed in:
7.38
Disclosed:
Feb 17, 2026

CVE-2026-1317 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress <= 7.35 - Authenticated (Contributor+) Server-Side Request Forgery via Bitly Shortlink Bypass

medium

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. While the initial UR...

CVSS:
6.4
Affected:
up to 7.35
Fixed in:
7.36
Disclosed:
Jan 1, 2026

CVE-2025-14627 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.36

unknown

[en] The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. While the initi...

Affected:
up to 7.36
Fixed in:
7.36
Disclosed:
Jan 1, 2026

CVE-2025-14627 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.34

unknown

[en] The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.33.1. This is due to deserialization of untrusted data supplied via CSV file imports in the import_single_post_as_csv function within SingleImportExport.php. Th...

Affected:
up to 7.34
Fixed in:
7.34
Disclosed:
Nov 19, 2025

CVE-2025-13145 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import

high

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.33.1. This is due to deserialization of untrusted data supplied via CSV file imports in the import_single_post_as_csv function within SingleImportExport.php. This ma...

CVSS:
7.2
Affected:
up to 7.33.1
Fixed in:
7.34
Disclosed:
Nov 18, 2025

CVE-2025-13145 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.33.1

unknown

[en] The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-l...

Affected:
up to 7.33.1
Fixed in:
7.33.1
Disclosed:
Nov 12, 2025

CVE-2025-12732 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information Exposure

medium

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level...

CVSS:
4.3
Affected:
up to 7.33
Fixed in:
7.33.1
Disclosed:
Nov 11, 2025

CVE-2025-12732 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] >= 7.20 - < 7.29

unknown

[en] The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to a file. This makes it possible for authenticated attackers, with Subscribe...

Affected:
7.20 – 7.29
Fixed in:
7.29
Disclosed:
Sep 17, 2025

CVE-2025-10057 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.28

unknown

[en] The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27. This makes it possible for authenticated attackers, with Subscriber-level acce...

Affected:
up to 7.28
Fixed in:
7.28
Disclosed:
Sep 17, 2025

CVE-2025-10058 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress 7.20 - 7.28 - Authenticated (Subscriber+) Remote Code Execution via Code Injection

high

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to a file. This makes it possible for authenticated attackers, with Subscriber-lev...

CVSS:
8.8
Affected:
7.20 – 7.28
Fixed in:
7.29
Disclosed:
Sep 16, 2025

CVE-2025-10057 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27. This makes it possible for authenticated attackers, with Subscriber-level access an...

CVSS:
8.1
Affected:
up to 7.27
Fixed in:
7.28
Disclosed:
Sep 16, 2025

CVE-2025-10058 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.28

unknown

[en] The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ftp_details' AJAX action in all versions up to, and including, 7.27. This makes it possible for authenticated attackers, with Subscriber-level acce...

Affected:
up to 7.28
Fixed in:
7.28
Disclosed:
Sep 10, 2025

CVE-2025-10040 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Missing Authorization to Authenticated (Subscriber+) FTP/SFTP Credential Exposure

high

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ftp_details' AJAX action in all versions up to, and including, 7.27. This makes it possible for authenticated attackers, with Subscriber-level access an...

CVSS:
7.7
Affected:
up to 7.27
Fixed in:
7.28
Disclosed:
Sep 9, 2025

CVE-2025-10040 on NVD →

Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import_single_post_as_csv() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and a...

CVSS:
8.8
Affected:
up to 7.19, 7.20 – 7.20
Fixed in:
7.19.1
Disclosed:
Mar 31, 2025

CVE-2025-2008 on NVD →

Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteImage() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

CVSS:
8.1
Affected:
up to 7.19, 7.20 – 7.20
Fixed in:
7.19.1
Disclosed:
Mar 25, 2025

CVE-2025-2007 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.7.3

unknown

[en] A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifie...

Affected:
up to 3.7.3
Fixed in:
3.7.3
Disclosed:
Oct 5, 2023

CVE-2015-10125 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.9.9

unknown

[en] The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to create a...

Affected:
up to 7.9.9
Fixed in:
7.9.9
Disclosed:
Aug 4, 2023

CVE-2023-4141 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.9.9

unknown

[en] The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such as an author, if the administrator p...

Affected:
up to 7.9.9
Fixed in:
7.9.9
Disclosed:
Aug 4, 2023

CVE-2023-4140 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.9.9

unknown

[en] The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated attackers to list and view exported files.

Affected:
up to 7.9.9
Fixed in:
7.9.9
Disclosed:
Aug 4, 2023

CVE-2023-4139 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.9.9

unknown

[en] The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to execute c...

Affected:
up to 7.9.9
Fixed in:
7.9.9
Disclosed:
Aug 4, 2023

CVE-2023-4142 on NVD →

WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution

high

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to create a PHP f...

CVSS:
8
Affected:
up to 7.9.8
Fixed in:
7.9.9
Disclosed:
Aug 3, 2023

CVE-2023-4141 on NVD →

WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution

high

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to execute code o...

CVSS:
8
Affected:
up to 7.9.8
Fixed in:
7.9.9
Disclosed:
Aug 3, 2023

CVE-2023-4142 on NVD →

WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing

high

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated attackers to list and view exported files.

CVSS:
7.5
Affected:
up to 7.9.8
Fixed in:
7.9.9
Disclosed:
Aug 3, 2023

CVE-2023-4139 on NVD →

WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation

medium

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such as an author, if the administrator previo...

CVSS:
6.6
Affected:
up to 7.9.8
Fixed in:
7.9.9
Disclosed:
Aug 3, 2023

CVE-2023-4140 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.5.8

unknown

[en] The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce

Affected:
up to 6.5.8
Fixed in:
6.5.8
Disclosed:
Oct 17, 2022

CVE-2022-3244 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.5.8

unknown

[en] The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

Affected:
up to 6.5.8
Fixed in:
6.5.8
Disclosed:
Oct 17, 2022

CVE-2022-3243 on NVD →

WP Ultimate CSV Importer <= 6.5.7 - Authenticated (Administrator+) SQL Injection

high

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
7.2
Affected:
up to 6.5.7
Fixed in:
6.5.8
Disclosed:
Sep 20, 2022

CVE-2022-3243 on NVD →

WP Ultimate CSV Importer <= 6.5.7 - Missing Authorization

medium

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on some of its functions in versions up to, and including, 6.5.7. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke them if they are able to...

CVSS:
5.4
Affected:
up to 6.5.7
Fixed in:
6.5.8
Disclosed:
Sep 20, 2022

CVE-2022-3244 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.5.3

unknown

[en] The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

Affected:
up to 6.5.3
Fixed in:
6.5.3
Disclosed:
Jun 27, 2022

CVE-2022-1977 on NVD →

WP Ultimate CSV Importer <= 6.5.2 - Server-Side Request Forgery

medium

The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

CVSS:
4.1
Affected:
up to 6.5.2
Fixed in:
6.5.3
Disclosed:
Jun 2, 2022

CVE-2022-1977 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.3

unknown

[en] The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues

Affected:
up to 6.4.3
Fixed in:
6.4.3
Disclosed:
Feb 28, 2022

CVE-2022-0360 on NVD →

WP Ultimate CSV Importer <= 6.4.2 - Admin+ Stored Cross-Site Scripting

medium

The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues

CVSS:
4.8
Affected:
up to 6.4.3
Fixed in:
6.4.3
Disclosed:
Jan 26, 2022

CVE-2022-0360 on NVD →

Import all XML, CSV & TXT into WordPress < 6.4.2 - Missing Authorization

high

The Import all XML, CSV & TXT into WordPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the disable_main_mode function in versions up to, and including, 6.4.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete...

CVSS:
7.1
Affected:
up to 6.4.1
Fixed in:
6.4.2
Disclosed:
Jan 17, 2022

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.2

unknown

Arbitrary Option Deletion vulnerability discovered by WPScanTeam in WordPress WP Ultimate CSV Importer plugin (versions <= 6.4.1).

Affected:
up to 6.4.2
Fixed in:
6.4.2
Disclosed:
Jan 17, 2022

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.2

unknown

The Import all XML, CSV & TXT into WordPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the disable_main_mode function in versions up to, and including, 6.4.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete...

Affected:
up to 6.4.2
Fixed in:
6.4.2
Disclosed:
Jan 17, 2022

WP Ultimate CSV Importer <= 6.4.0 - Arbitrary File Upload

high

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip_upload AJAX call in versions up to, and including, 6.4.0. This makes it possible for subscriber-level attackers to upload arbitrary files on the affected sites server which may make r...

CVSS:
8.8
Affected:
up to 6.4.0
Fixed in:
6.4.1
Disclosed:
Jan 12, 2022

Easy Drag And drop All Import : WP Ultimate CSV Importer < 6.4.1 - Missing Authorization Checks

medium

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions like upload_function(), display_log(), download_log(), display_csv_values(), etc... in versions up to 6.4.1. This makes it possible for authenticated attackers with minimal perm...

CVSS:
6.3
Affected:
up to 6.4.1
Fixed in:
6.4.1
Disclosed:
Jan 12, 2022

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.1

unknown

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip_upload AJAX call in versions up to, and including, 6.4.0. This makes it possible for subscriber-level attackers to upload arbitrary files on the affected sites server which may make r...

Affected:
up to 6.4.1
Fixed in:
6.4.1
Disclosed:
Jan 12, 2022

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.1

unknown

Plugin Settings Update vulnerability discovered in WordPress WP Ultimate CSV Importer plugin (versions <= 6.4).

Affected:
up to 6.4.1
Fixed in:
6.4.1
Disclosed:
Jan 12, 2022

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.1

unknown

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions like upload_function(), display_log(), download_log(), display_csv_values(), etc... in versions up to 6.4.1. This makes it possible for authenticated attackers with minimal perm...

Affected:
up to 6.4.1
Fixed in:
6.4.1
Disclosed:
Jan 12, 2022

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.1

unknown

Arbitrary Media File Deletion vulnerability (restricted to the uploads folder of the current year/month) discovered in WordPress WP Ultimate CSV Importer plugin (versions <= 6.4).

Affected:
up to 6.4.1
Fixed in:
6.4.1
Disclosed:
Jan 12, 2022

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.1

unknown

Arbitrary File Upload vulnerability discovered in WordPress WP Ultimate CSV Importer plugin (versions <= 6.4).

Affected:
up to 6.4.1
Fixed in:
6.4.1
Disclosed:
Jan 12, 2022

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 5.6.1

unknown

[en] The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

Affected:
up to 5.6.1
Fixed in:
5.6.1
Disclosed:
Aug 14, 2019

CVE-2018-20967 on NVD →

Easy Drag And drop All Import : WP Ultimate CSV Importer <= 5.6 - Cross-Site Request Forgery

high

The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

CVSS:
8.8
Affected:
up to 5.6
Fixed in:
5.6.1
Disclosed:
Aug 13, 2019

CVE-2018-20967 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.8.1

unknown

[en] The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.

Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
Aug 12, 2019

CVE-2015-9306 on NVD →

Import Export All WordPress Images, Users & Post Types <= 3.8.7 - Reflected Cross-Site Scripting

medium

The Import Export All WordPress Images, Users & Post Types plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alertmsg’ parameter in versions up to, and including, 3.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
6.1
Affected:
up to 3.8.8
Fixed in:
3.8.8
Disclosed:
Jan 27, 2018

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.8.8

unknown

The Import Export All WordPress Images, Users & Post Types plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alertmsg’ parameter in versions up to, and including, 3.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Affected:
up to 3.8.8
Fixed in:
3.8.8
Disclosed:
Jan 27, 2018

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.8.8

unknown

This plugin is prone to a cross site scripting vulnerability, because "alertmsg" parameter is not sanitized. Update the plugin.

Affected:
up to 3.8.8
Fixed in:
3.8.8
Disclosed:
Jan 27, 2016

Easy Drag And drop All Import : WP Ultimate CSV Importer < 3.8.1 - Cross-Site Scripting

medium

The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
Aug 18, 2015

CVE-2015-9306 on NVD →

Import CSV or XML Datafeed With Ease <= 3.7.2 - Cross-Site Request Forgery

medium

The Import CSV or XML Datafeed With Ease plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.7.2. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform unauthorized actions via a fo...

CVSS:
4.3
Affected:
up to 3.7.2
Fixed in:
3.7.3
Disclosed:
May 5, 2015

CVE-2015-10125 on NVD →

WP Ultimate CSV Importer <= 3.7 - Arbitrary File Read

high

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the templates/readfile.php file in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to read any files on the vulnerable service that PHP has access to.

CVSS:
7.5
Affected:
up to 3.7
Fixed in:
3.7.1
Disclosed:
Apr 27, 2015

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.7.1

unknown

Because of this vulnerability, the attackers can read files on the filesystem without authorization. Update the plugin.

Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Apr 27, 2015

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.7.1

unknown

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the templates/readfile.php file in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to read any files on the vulnerable service that PHP has access to.

Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Apr 27, 2015

Ultimate CSV Importer < 3.6.75 - Information Disclosure

high

The Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.74 via the modules/export/templates/export.php file. This can allow unauthenticated attackers to extract sensitive data including emails, passwords and usernames.

CVSS:
7.5
Affected:
up to 3.6.75
Fixed in:
3.6.75
Disclosed:
Feb 22, 2015

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.6.75

unknown

Because of this vulnerability, remote attackers can disclose usernames, hashed passwords and email addresses for all users. Update the plugin.

Affected:
up to 3.6.75
Fixed in:
3.6.75
Disclosed:
Feb 22, 2015

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.6.75

unknown

The Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.74 via the modules/export/templates/export.php file. This can allow unauthenticated attackers to extract sensitive data including emails, passwords and usernames.

Affected:
up to 3.6.75
Fixed in:
3.6.75
Disclosed:
Feb 22, 2015

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.8.8

unknown

The Import and Export WordPress Data as CSV or XML WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 3.8.8
Fixed in:
3.8.8

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.1

unknown

The plugin does not have authorisation and CSRF checks when uploading zip files via the zip_upload AJAX call, and does not perform any check on the files to be extracted. As a result, any authenticated user, such as subscriber could upload an archive with PHP files in it, leading to RCE

Affected:
up to 6.4.1
Fixed in:
6.4.1

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.20.1

unknown
Affected:
up to 7.20.1
Fixed in:
7.20.1

CVE-2025-2007 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 7.20.1

unknown
Affected:
up to 7.20.1
Fixed in:
7.20.1

CVE-2025-2008 on NVD →

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 6.4.2

unknown

The plugin does not have authorisation and CSRF checks when deleting options via the disable_main_mode AJAX action, and does not ensure that the option to be delete belong to the plugin. As a result, any authenticated user, such as subscriber, could delete arbitrary options from the blog

Affected:
up to 6.4.2
Fixed in:
6.4.2

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.6.75

unknown

Due to lack of verification of a visitors permissions, it is possible to execute the &lsquo;export.php&rsquo; script included in the default installation of this plugin, and retrieve the full contents of the user table in the WordPress installation. This results in full disclosure of usernames, hashed passwords and ema...

Affected:
up to 3.6.75
Fixed in:
3.6.75

WP Import – Ultimate CSV XML Importer for WordPress [wp-ultimate-csv-importer] < 3.7.1

unknown

The Import and Export WordPress Data as CSV or XML WordPress plugin was affected by a Directory Traversal security vulnerability.

Affected:
up to 3.7.1
Fixed in:
3.7.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database