Wpallimport
Wpallimport WP ALL Import: vulnerabilidades y CVE
Wpallimport WP ALL Import tiene 4 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57628 | Alta (7.6) | 0.38% | — | 26 jun 2026 | Administrator SQL Injection in WP All Import <= 4.0.1 versions. |
| CVE-2025-12733 | Alta (8.8) | 0.64% | — | 13 nov 2025 | The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval() on unsanitized… |
| CVE-2024-32431 | Alta (7.2) | 0.38% | — | 15 abr 2024 | Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2. |
| CVE-2022-1565 | Alta (7.2) | 15% | — | 18 jul 2022 | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.