Vjinfotech's vulnerability profile centers on WordPress plugins focused on import, export, and order-management functionality, a modestly represented niche in the plugin ecosystem. The recurring exposure reflects the plugin context itself: insecure file uploads, cross-site request forgery, unsafe deserialization, cross-site scripting, and missing authorization checks are common to web applications that handle user input and manage sensitive administrative operations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vjinfotech over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6207HIGH The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up | Aug 5, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-5061HIGH The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions | Aug 5, 2025 | 8.8 | 29 | NO | NO |
CVE-2026-11397MEDIUM The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX | Jul 3, 2026 | 5.5 | 28 | NO | NO |
CVE-2023-47687HIGH Cross-Site Request Forgery (CSRF) vulnerability in VJInfotech Woo Custom and Sequential Order Number plugin <= 2.6.0 versions. | Nov 16, 2023 | 8.8 | 21 | NO | NO |
CVE-2022-0236HIGH The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download | Jan 18, 2022 | 7.5 | 20 | NO | NO |
CVE-2025-2839MEDIUM The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, 3.9.27 due to i | Apr 22, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-31308HIGH Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26. | Apr 7, 2024 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vjinfotech.
Media articles that mention a CVE ID that affects a product developed by Vjinfotech — matched by CVE ID, not by vendor name.