WP All Import is a WordPress plugin focused on data import and migration functionality, where the observed vulnerability exposure centers on deserialization of untrusted data and unrestricted file uploads—both characteristic of plugins that must accept and process external content. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpallimport over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1565HIGH The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. | Jul 18, 2022 | 7.2 | 42 | NO | YES |
CVE-2026-57628HIGH Administrator SQL Injection in WP All Import <= 4.0.1 versions. | Jun 26, 2026 | 7.6 | 32 | NO | NO |
CVE-2024-32431HIGH Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2. | Apr 15, 2024 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpallimport.
Media articles that mention a CVE ID that affects a product developed by Wpallimport — matched by CVE ID, not by vendor name.