| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-32441 | WordPress Comments Import & Export plugin <= 2.4.9 - Broken Access Control vulnerability | WebToffee | Comments Import & Export | 中危 | - | 2026-03-25 16:14:57 | Deep Dive |
| CVE-2026-3629 | Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields | carazo | Import and export users and customers | High | 8.1 | 2026-03-21 22:24:18 | Deep Dive |
| CVE-2026-32731 | ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction | apostrophecms | import-export | Critical | 9.9 | 2026-03-18 22:03:26 | Deep Dive |
| CVE-2025-7016 | Improper Access Control in Akinsoft's QR Menu | Akın Software Computer Import Export Industry and Trade Ltd. | QR Menu | High | 8.0 | 2026-01-29 11:45:06 | Deep Dive |
| CVE-2025-7015 | Session Hijacking in Akinsoft's QR Menu | Akın Software Computer Import Export Industry and Trade Ltd. | QR Menu | Medium | 5.7 | 2026-01-29 11:40:47 | Deep Dive |
| CVE-2025-14050 | Design Import/Export <= 2.2 - Authenticated (Administrator+) SQL Injection via XML File Import | uxl | Design Import/Export – Styles, Templates, Template Parts and Patterns | Medium | 4.9 | 2025-12-13 03:20:27 | Deep Dive |
| CVE-2025-12894 | Import WP – Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure | jcollings | Import WP – Export and Import CSV and XML files to WordPress | Medium | 5.3 | 2025-11-21 07:31:49 | Deep Dive |
| CVE-2025-13133 | Simple User Import Export <= 1.1.7 - Authenticated (Admin+) CSV Injection | vaniivan | Simple User Import Export | Medium | 6.6 | 2025-11-18 09:27:37 | Deep Dive |
| CVE-2025-64382 | WordPress Order Export & Order Import for WooCommerce plugin <= 2.6.7 - Broken Access Control vulnerability | WebToffee | Order Export & Order Import for WooCommerce | 中危 | - | 2025-11-13 09:24:35 | Deep Dive |
| CVE-2025-60200 | WordPress LearnPress Export Import plugin <= 4.1.2 - Local File Inclusion vulnerability | ThimPress | LearnPress Export Import | High | 7.5 | 2025-11-06 15:55:00 | Deep Dive |
| CVE-2025-12389 | Import Export For WooCommerce <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update | sidngr | Import Export For WooCommerce | Medium | 4.3 | 2025-11-04 04:27:21 | Deep Dive |
| CVE-2025-12137 | Import WP – Export and Import CSV and XML files to WordPress <= 2.14.16 - Authenticated (Admin+) Arbitrary File Read | jcollings | Import WP – Export and Import CSV and XML files to WordPress | Medium | 4.9 | 2025-11-01 06:40:40 | Deep Dive |
| CVE-2025-49992 | WordPress LearnPress Export Import plugin <= 4.0.9 - Cross Site Scripting (XSS) vulnerability | ThimPress | LearnPress Export Import | - | - | 2025-10-22 14:32:22 | Deep Dive |
| CVE-2025-9902 | IDOR in Akınsoft QRMenu | AKIN Software Computer Import Export Industry and Trade Co. Ltd. | QRMenu | High | 7.5 | 2025-10-13 13:06:53 | Deep Dive |
| CVE-2025-54029 | WordPress WooCommerce csv import export Plugin <= 2.0.6 - Arbitrary File Deletion Vulnerability | extendons | WooCommerce csv import export | High | 7.7 | 2025-08-28 12:37:34 | Deep Dive |
| CVE-2025-5061 | WP Import Export Lite <= 3.9.29 - Authenticated (Subscriber+) Arbitrary File Upload | vjinfotech | WP Import Export Lite | High | 7.5 | 2025-08-05 07:24:16 | Deep Dive |
| CVE-2025-6207 | WP Import Export Lite <= 3.9.28 - Authenticated (Subscriber+) Arbitrary File Upload | vjinfotech | WP Import Export Lite | High | 7.5 | 2025-08-05 07:24:15 | Deep Dive |
| CVE-2020-36849 | AIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File Upload | AIT Themes | AIT CSV import/export | Critical | 9.8 | 2025-07-12 11:23:40 | Deep Dive |
| CVE-2025-5288 | REST API | Custom API Generator For Cross Platform And Import Export In WP 1.0.0 - 2.0.3 - Missing Authorization to Unauthenticated Privilege Escalation via process_handler Function | weboccults | REST API | Custom API Generator For Cross Platform And Import Export In WP | Critical | 9.8 | 2025-06-13 01:47:46 | Deep Dive |
| CVE-2025-3919 | WordPress Comments Import & Export <= 2.4.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | webtoffee | Comments Import & Export | Medium | 6.4 | 2025-06-02 22:22:36 | Deep Dive |