← WordPress Vulnerabilities
WordPress security by component

WP All Import

WP All Import is a WordPress component with 24 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: wp-all-import

CVE-2026-57628: WP All Import: SQL injection

WP All Import is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 4.0.1.

PublishedJun 26, 2026
Known safe version4.1.0
Safe version
Jun 26, 2026 CVE-2026-57628
WP All Import: SQL injection
WP All Import is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 4.0.1.
4.1.0
CVE7.6
NVDPending
Mar 06, 2026 CVE-2026-2830
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets: Cross-site scripting
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Nov 13, 2025 CVE-2025-12733
Import any XML, CSV or Excel File to WordPress (WP All Import): Code execution
Import any XML, CSV or Excel File to WordPress (WP All Import) is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Feb 07, 2025 CVE-2024-9664
WP All Import Pro: Code execution
WP All Import Pro is affected by code execution. Exploitation requires at least administrator-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
Apr 10, 2024 CVE-2024-31939
Import any XML or CSV File to WordPress: Cross-site request forgery
Import any XML or CSV File to WordPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 07, 2022 CVE-2022-3418
Import any XML or CSV File to: A security weakness
Import any XML or CSV File to is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Nov 07, 2022 CVE-2022-2711
Import any XML or CSV File to: Filesystem traversal
Import any XML or CSV File to is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.2
NVD7.2
Sep 21, 2022 CVE-2022-36386
Wp All Import: Code execution
Wp All Import is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.1
NVD7.2
Jul 18, 2022 CVE-2022-1565
Wp All Import: Dangerous file upload
Wp All Import is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE7.2
NVD7.2
Jul 04, 2022 CVE-2022-2268
Import any XML or CSV File to: A security weakness
Import any XML or CSV File to is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Dec 06, 2021 CVE-2021-24714
Import any XML or CSV File to: A security weakness
Import any XML or CSV File to is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.8
NVD4.8
Aug 20, 2019 CVE-2018-20978
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 20, 2019 CVE-2017-18567
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 20, 2019 CVE-2015-9331
Wp All Import: A security weakness
Wp All Import is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 20, 2019 CVE-2015-9330
Wp All Import: SQL injection
Wp All Import is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Aug 20, 2019 CVE-2015-9329
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 12, 2019 CVE-2018-16259
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 12, 2019 CVE-2018-16258
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 12, 2019 CVE-2018-16257
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 12, 2019 CVE-2018-16256
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 12, 2019 CVE-2018-16255
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 12, 2019 CVE-2018-16254
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 09, 2018 CVE-2018-0547
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 09, 2018 CVE-2018-0546
Wp All Import: Cross-site scripting
Wp All Import is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1