Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesWP All Import

WP All Import vulnerabilities

WP All Import has 23 known vulnerabilities in this database. The most recent published record is dated 6 Mar 2026.

Known vulnerabilities
23
Active installs
100,000+
Latest version
4.1.2
Last updated
1 Oct 2026
Most recent
6 Mar 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-2830
Medium 6.1Up to 4.0.0Fixed in a later version (latest 4.1.2)6 Mar 2026
Remote code execution
CVE-2025-12733
High 8.8Up to 3.9.6Fixed in a later version (latest 4.1.2)13 Nov 2025
Remote code execution
CVE-2025-10001
High 7.2Up to 3.9.3Fixed in a later version (latest 4.1.2)10 Sep 2025
PHP object injection
CVE-2024-9664
High 7.2Before 4.9.8Fixed in 4.9.87 Feb 2025
Cross-site request forgery (CSRF)
CVE-2024-31939
Medium 4.3Up to 3.7.3Fixed in a later version (latest 4.1.2)10 Apr 2024
Path traversal
CVE-2022-2711
High 7.2Before 3.6.9Fixed in 3.6.97 Nov 2022
Remote code execution
CVE-2022-3418
High 7.2Before 3.6.9Fixed in 3.6.97 Nov 2022
Arbitrary file upload
CVE-2022-36386
Critical 9.1Up to 3.6.7Fixed in a later version (latest 4.1.2)21 Sep 2022
Remote code execution
CVE-2022-2268
High 7.2Before 3.6.8Fixed in 3.6.84 Jul 2022
Cross-site scripting (XSS)
CVE-2021-24714
Medium 4.8Before 3.6.3Fixed in 3.6.36 Dec 2021
Cross-site scripting (XSS)
CVE-2018-20978
Medium 6.1Before 3.4.7Fixed in 3.4.720 Aug 2019
Cross-site scripting (XSS)
CVE-2015-9329
Medium 6.1Before 3.2.5Fixed in 3.2.520 Aug 2019
SQL injection
CVE-2015-9330
Critical 9.8Before 3.2.5Fixed in 3.2.520 Aug 2019
Security weakness
CVE-2015-9331
High 7.5Before 3.2.4Fixed in 3.2.420 Aug 2019
Cross-site scripting (XSS)
CVE-2017-18567
Medium 6.1Before 3.2.6Fixed in 3.2.620 Aug 2019
Cross-site scripting (XSS)
CVE-2018-16257
Medium 6.1Not yet publishedCheck for an update12 Apr 2019
Cross-site scripting (XSS)
CVE-2018-16258
Medium 6.1Not yet publishedCheck for an update12 Apr 2019
Cross-site scripting (XSS)
CVE-2018-16259
Medium 6.1Not yet publishedCheck for an update12 Apr 2019
Cross-site scripting (XSS)
CVE-2018-16254
Medium 6.1Not yet publishedCheck for an update12 Apr 2019
Cross-site scripting (XSS)
CVE-2018-16255
Medium 6.1Not yet publishedCheck for an update12 Apr 2019
Cross-site scripting (XSS)
CVE-2018-16256
Medium 6.1Not yet publishedCheck for an update12 Apr 2019
Cross-site scripting (XSS)
CVE-2018-0546
Medium 6.1Before 3.4.6Fixed in 3.4.69 Mar 2018
Cross-site scripting (XSS)
CVE-2018-0547
Medium 6.1Up to 3.4.6Fixed in a later version (latest 4.1.2)9 Mar 2018
Read the published descriptions
CVE-2026-2830, 6 Mar 2026
The WP All Import - Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2025-12733, 13 Nov 2025
The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval() on unsanitized user-supplied input in the pmxi_if function within helpers/functions.php. This makes it possible for authenticated attackers, with import capabilities (typically administrators), to inject and execute arbitrary PHP code on the server via crafted import templates. This can lead to remote code execution. CVE record
CVE-2025-10001, 10 Sep 2025
The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload unsafe files like .phar files on the affected site's server which may make remote code execution possible. CVE record
CVE-2024-9664, 7 Feb 2025
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. CVE record
CVE-2024-31939, 10 Apr 2024
Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Import any XML or CSV File to WordPress.This issue affects Import any XML or CSV File to WordPress: from n/a through 3.7.3. CVE record
CVE-2022-2711, 7 Nov 2022
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector. CVE record
CVE-2022-3418, 7 Nov 2022
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files CVE record
CVE-2022-36386, 21 Sep 2022
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. CVE record
CVE-2022-2268, 4 Jul 2022
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE CVE record
CVE-2021-24714, 6 Dec 2021
The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed. CVE record
CVE-2018-20978, 20 Aug 2019
The wp-all-import plugin before 3.4.7 for WordPress has XSS. CVE record
CVE-2015-9329, 20 Aug 2019
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS. CVE record
CVE-2015-9330, 20 Aug 2019
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. CVE record
CVE-2015-9331, 20 Aug 2019
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit. CVE record
CVE-2017-18567, 20 Aug 2019
The wp-all-import plugin before 3.4.6 for WordPress has XSS. CVE record
CVE-2018-16257, 12 Apr 2019
There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
CVE-2018-16258, 12 Apr 2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
CVE-2018-16259, 12 Apr 2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
CVE-2018-16254, 12 Apr 2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
CVE-2018-16255, 12 Apr 2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
CVE-2018-16256, 12 Apr 2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator CVE record
CVE-2018-0546, 9 Mar 2018
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. CVE record
CVE-2018-0547, 9 Mar 2018
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. CVE record

What to do if you run WP All Import

If you run WP All Import, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new WP All Import vulnerabilities

Free. We email you when a new vulnerability is published for WP All Import, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support