Wp All Import
Vendor:
First CVE: Mar 9, 2018 · Active for 8 years
19
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wp All Import over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 9, 2018
8 years ago
Most Recent CVE
Feb 7, 2025
536 days ago
CVE Severity & Scoring
Wp All Import19 CVEs
63%
32%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (36.8%)
Unknown0 (0.0%)
Required12 (63.2%)
Privileges Required
Low0 (0.0%)
High6 (31.6%)
None13 (68.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2711HIGH The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as a | Nov 7, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-3418HIGH The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administ | Nov 7, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-36386HIGH Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. | Sep 21, 2022 | 7.2 | 24 | NO | NO |
CVE-2015-9330CRITICAL The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. | Aug 20, 2019 | 9.8 | 24 | NO | NO |
CVE-2015-9331HIGH The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit. | Aug 20, 2019 | 7.5 | 22 | NO | NO |
CVE-2018-16259MEDIUM There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All | Apr 12, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-16258MEDIUM There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import | Apr 12, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-16257MEDIUM There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is o | Apr 12, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-16256MEDIUM There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Impo | Apr 12, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-16255MEDIUM There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able | Apr 12, 2019 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Wp All Import
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.4.9 | 6 | 6.1 | 0.9% | 0 | 0 |