All 4 CVE vulnerabilities found in WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets, with AI-generated Chinese analysis, references, and POCs.
Vendor: wpallimport
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-2830 | WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath' CWE-94 | 6.1 | Medium | 2026-03-06 |
| CVE-2025-12733 | Import any XML, CSV or Excel File to WordPress (WP All Import) <= 3.9.6 - Authenticated (Administrator+) Remote Code Execution via Conditional Logic CWE-94 | 8.8 | High | 2025-11-13 |
| CVE-2025-10001 | Import any XML, CSV or Excel File to WordPress <= 3.9.3 - Authenticated (Admin+) Limited Unsafe File Upload CWE-434 | 7.2 | High | 2025-09-10 |
| CVE-2022-1565 | Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload CWE-434 | 7.2 | High | 2022-07-18 |
All 4 known CVE vulnerabilities affecting WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets with full Chinese analysis, references, and POCs where available.