ImportWP is a WordPress import and data-migration plugin with a narrowly scoped vulnerability footprint centered on the Import WP product. The durable signal reflects exposure risks inherent to file-handling and external-data-integration features: recurring weakness classes include sensitive-information disclosure, server-side request forgery, unrestricted file uploads, and incomplete vulnerability classification, all typical of data-processing plugins that accept user-supplied content and external sources. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Importwp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13562HIGH The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 v | Jan 25, 2025 | 7.5 | 22 | NO | NO |
CVE-2022-1273HIGH The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), | May 2, 2022 | 7.2 | 20 | NO | NO |
CVE-2023-7253MEDIUM The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configura | Apr 24, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Importwp.
Media articles that mention a CVE ID that affects a product developed by Importwp — matched by CVE ID, not by vendor name.