CVE-2024-9664
- EPSS 0.98%
- Veröffentlicht 07.02.2025 16:15:39
- Zuletzt bearbeitet 11.02.2025 19:16:44
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers, with Administ...
CVE-2024-8722
- EPSS 0.18%
- Veröffentlicht 19.01.2025 05:15:07
- Zuletzt bearbeitet 19.01.2025 05:15:07
The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes ...
CVE-2022-3418
- EPSS 1.36%
- Veröffentlicht 07.11.2022 10:15:11
- Zuletzt bearbeitet 01.05.2025 21:15:50
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files
CVE-2022-2711
- EPSS 0.89%
- Veröffentlicht 07.11.2022 10:15:11
- Zuletzt bearbeitet 05.05.2025 21:15:46
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessi...
CVE-2022-36386
- EPSS 5.77%
- Veröffentlicht 21.09.2022 20:15:10
- Zuletzt bearbeitet 20.02.2025 20:15:35
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
CVE-2022-2268
- EPSS 0.96%
- Veröffentlicht 04.07.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:39
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP...
CVE-2021-24714
- EPSS 0.21%
- Veröffentlicht 06.12.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:53:37
The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the ...
CVE-2018-20978
- EPSS 0.21%
- Veröffentlicht 20.08.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:02:36
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
CVE-2015-9331
- EPSS 0.55%
- Veröffentlicht 20.08.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:40:22
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
CVE-2017-18567
- EPSS 0.21%
- Veröffentlicht 20.08.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 03:20:25
The wp-all-import plugin before 3.4.6 for WordPress has XSS.