HomeWordPress vulnerabilitiesWP All Import
WP All Import vulnerabilities
WP All Import has 23 known vulnerabilities in this database. The most recent published record is dated 6 Mar 2026.
- Known vulnerabilities
- 23
- Active installs
- 100,000+
- Latest version
- 4.1.2
- Last updated
- 1 Oct 2026
- Most recent
- 6 Mar 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-2830 | Medium 6.1 | Up to 4.0.0 | Fixed in a later version (latest 4.1.2) | 6 Mar 2026 |
| Remote code execution CVE-2025-12733 | High 8.8 | Up to 3.9.6 | Fixed in a later version (latest 4.1.2) | 13 Nov 2025 |
| Remote code execution CVE-2025-10001 | High 7.2 | Up to 3.9.3 | Fixed in a later version (latest 4.1.2) | 10 Sep 2025 |
| PHP object injection CVE-2024-9664 | High 7.2 | Before 4.9.8 | Fixed in 4.9.8 | 7 Feb 2025 |
| Cross-site request forgery (CSRF) CVE-2024-31939 | Medium 4.3 | Up to 3.7.3 | Fixed in a later version (latest 4.1.2) | 10 Apr 2024 |
| Path traversal CVE-2022-2711 | High 7.2 | Before 3.6.9 | Fixed in 3.6.9 | 7 Nov 2022 |
| Remote code execution CVE-2022-3418 | High 7.2 | Before 3.6.9 | Fixed in 3.6.9 | 7 Nov 2022 |
| Arbitrary file upload CVE-2022-36386 | Critical 9.1 | Up to 3.6.7 | Fixed in a later version (latest 4.1.2) | 21 Sep 2022 |
| Remote code execution CVE-2022-2268 | High 7.2 | Before 3.6.8 | Fixed in 3.6.8 | 4 Jul 2022 |
| Cross-site scripting (XSS) CVE-2021-24714 | Medium 4.8 | Before 3.6.3 | Fixed in 3.6.3 | 6 Dec 2021 |
| Cross-site scripting (XSS) CVE-2018-20978 | Medium 6.1 | Before 3.4.7 | Fixed in 3.4.7 | 20 Aug 2019 |
| Cross-site scripting (XSS) CVE-2015-9329 | Medium 6.1 | Before 3.2.5 | Fixed in 3.2.5 | 20 Aug 2019 |
| SQL injection CVE-2015-9330 | Critical 9.8 | Before 3.2.5 | Fixed in 3.2.5 | 20 Aug 2019 |
| Security weakness CVE-2015-9331 | High 7.5 | Before 3.2.4 | Fixed in 3.2.4 | 20 Aug 2019 |
| Cross-site scripting (XSS) CVE-2017-18567 | Medium 6.1 | Before 3.2.6 | Fixed in 3.2.6 | 20 Aug 2019 |
| Cross-site scripting (XSS) CVE-2018-16257 | Medium 6.1 | Not yet published | Check for an update | 12 Apr 2019 |
| Cross-site scripting (XSS) CVE-2018-16258 | Medium 6.1 | Not yet published | Check for an update | 12 Apr 2019 |
| Cross-site scripting (XSS) CVE-2018-16259 | Medium 6.1 | Not yet published | Check for an update | 12 Apr 2019 |
| Cross-site scripting (XSS) CVE-2018-16254 | Medium 6.1 | Not yet published | Check for an update | 12 Apr 2019 |
| Cross-site scripting (XSS) CVE-2018-16255 | Medium 6.1 | Not yet published | Check for an update | 12 Apr 2019 |
| Cross-site scripting (XSS) CVE-2018-16256 | Medium 6.1 | Not yet published | Check for an update | 12 Apr 2019 |
| Cross-site scripting (XSS) CVE-2018-0546 | Medium 6.1 | Before 3.4.6 | Fixed in 3.4.6 | 9 Mar 2018 |
| Cross-site scripting (XSS) CVE-2018-0547 | Medium 6.1 | Up to 3.4.6 | Fixed in a later version (latest 4.1.2) | 9 Mar 2018 |
Read the published descriptions
- CVE-2026-2830, 6 Mar 2026
- The WP All Import - Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2025-12733, 13 Nov 2025
- The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval() on unsanitized user-supplied input in the pmxi_if function within helpers/functions.php. This makes it possible for authenticated attackers, with import capabilities (typically administrators), to inject and execute arbitrary PHP code on the server via crafted import templates. This can lead to remote code execution. CVE record
- CVE-2025-10001, 10 Sep 2025
- The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload unsafe files like .phar files on the affected site's server which may make remote code execution possible. CVE record
- CVE-2024-9664, 7 Feb 2025
- The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. CVE record
- CVE-2024-31939, 10 Apr 2024
- Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Import any XML or CSV File to WordPress.This issue affects Import any XML or CSV File to WordPress: from n/a through 3.7.3. CVE record
- CVE-2022-2711, 7 Nov 2022
- The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector. CVE record
- CVE-2022-3418, 7 Nov 2022
- The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files CVE record
- CVE-2022-36386, 21 Sep 2022
- Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. CVE record
- CVE-2022-2268, 4 Jul 2022
- The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE CVE record
- CVE-2021-24714, 6 Dec 2021
- The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed. CVE record
- CVE-2018-20978, 20 Aug 2019
- The wp-all-import plugin before 3.4.7 for WordPress has XSS. CVE record
- CVE-2015-9329, 20 Aug 2019
- The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS. CVE record
- CVE-2015-9330, 20 Aug 2019
- The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. CVE record
- CVE-2015-9331, 20 Aug 2019
- The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit. CVE record
- CVE-2017-18567, 20 Aug 2019
- The wp-all-import plugin before 3.4.6 for WordPress has XSS. CVE record
- CVE-2018-16257, 12 Apr 2019
- There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
- CVE-2018-16258, 12 Apr 2019
- There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
- CVE-2018-16259, 12 Apr 2019
- There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
- CVE-2018-16254, 12 Apr 2019
- There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
- CVE-2018-16255, 12 Apr 2019
- There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
- CVE-2018-16256, 12 Apr 2019
- There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
- CVE-2018-0546, 9 Mar 2018
- Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. CVE record
- CVE-2018-0547, 9 Mar 2018
- Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. CVE record
What to do if you run WP All Import
If you run WP All Import, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new WP All Import vulnerabilities
Free. We email you when a new vulnerability is published for WP All Import, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.