VendorsSoflyywp_all_importany version
Vulnerabilities

Soflyy WP All Import any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2015-9330
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
Published 2019-08-20 · Modified
9.8EPSS 0.018
CVE-2022-36386
WordPress Import any XML or CSV File to WordPress plugin <= 3.6.7 - Authenticated Arbitrary Code Execution vulnerability
Published 2022-09-21 · Modified
9.1EPSS 0.015
CVE-2015-9331
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
Published 2019-08-20 · Modified
7.5EPSS 0.014
CVE-2022-2711
WP All Import < 3.6.9 - Admin+ Directory traversal via file upload
Published 2022-11-07 · Modified
7.2EPSS 0.035
CVE-2022-2268
WP All Import < 3.6.8 - Admin+ Arbitrary File Upload
Published 2022-07-04 · Modified
7.2EPSS 0.014
CVE-2022-3418
WP All Import < 3.6.9 - Admin+ Arbitrary File Upload to RCE
Published 2022-11-07 · Modified
7.2EPSS 0.012
CVE-2024-9664
WP All Import Pro <= 4.9.7 - Authenticated (Administrator+) PHP Object Injection via Import File
Published 2025-02-07 · Analyzed
7.2EPSS 0.007
CVE-2018-0546
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
Published 2018-03-09 · Modified
6.1EPSS 0.015
CVE-2018-0547
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
Published 2018-03-09 · Modified
6.1EPSS 0.015
CVE-2015-9329
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
Published 2019-08-20 · Modified
6.1EPSS 0.009
CVE-2017-18567
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
Published 2019-08-20 · Modified
6.1EPSS 0.009
CVE-2018-20978
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
Published 2019-08-20 · Modified
6.1EPSS 0.009
CVE-2021-24714
WP All Import < 3.6.3 - Admin+ Stored Cross-Site Scripting
Published 2021-12-06 · Modified
4.8EPSS 0.006