Cross-Site Scripting
8 records34.8%First: 2015. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 23 vulnerability records associated with WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets, published between 2015 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 2 | |
| 2017 | 1 | |
| 2018 | 3 | |
| 2019 | 1 | |
| 2020 | 2 | |
| 2021 | 1 | |
| 2022 | 6 | |
| 2023 | 1 | |
| 2024 | 1 | |
| 2025 | 3 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 8.7% |
| High | 6 | 26.1% |
| Medium | 13 | 56.5% |
| Low | 1 | 4.3% |
| Informational | 1 | 4.3% |
First: 2015. Latest: 2026.
First: 2022. Latest: 2025.
First: 2015. Latest: 2026.
First: 2022. Latest: 2025.
First: 2019. Latest: 2020.
First: 2022. Latest: 2022.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.1.04.0.14.0.03.9.43.9.03.7.43.7.33.6.93.6.83.6.73.6.33.2.43.4.63.4.73.2.5Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.0.1 | WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets <= 4.0.1 - Authenticated (Administrator+) SQL Injection | June 26, 2026 | 4.1.0 | Medium |
*-4.0.0 | WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath' | March 5, 2026 | 4.0.1 | Medium |
*-3.9.6 | Import any XML, CSV or Excel File to WordPress (WP All Import) <= 3.9.6 - Authenticated (Administrator+) Remote Code Execution via Conditional Logic | November 12, 2025 | 4.0.0 | High |
*-3.9.3 | Import any XML, CSV or Excel File to WordPress <= 3.9.3 - Authenticated (Admin+) Limited Unsafe File Upload | September 9, 2025 | 3.9.4 | High |
*-3.8.0 | Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 - Use of Vulnerable Component (PHPExcel) | April 7, 2025 | 3.9.0 | Low |
*-3.7.3 | Import any XML or CSV File to WordPress <= 3.7.3 - Cross-Site Request Forgery to Notice Dismissal | April 10, 2024 | 3.7.4 | Medium |
[*, 3.7.3) | Import any XML or CSV File <= 3.7.2 - Authenticated (Admin+) Arbitrary File Upload | December 29, 2023 | 3.7.3 | High |
*-3.6.8 | Import any XML or CSV File to WordPress <= 3.6.8 - Authenticated (Administrator+) Arbitrary File Upload | October 17, 2022 | 3.6.9 | Medium |
*-3.6.8 | Import any XML or CSV File to WordPress <= 3.6.8 - Authenticated (Administrator+) Arbitrary File Upload via Path Traversal | October 17, 2022 | 3.6.9 | Medium |
*-3.6.7 | WP All Import <= 3.6.7 - Admin+ Arbitrary File Upload | July 1, 2022 | 3.6.8 | Medium |
*-3.6.7 | Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload | June 30, 2022 | 3.6.8 | High |
*-3.6.7 | WP All Import <= 3.6.7 - Authenticated (Administrator+) Arbitrary Code Execution | June 28, 2022 | 3.6.8 | Critical |
*-3.6.6 | Import any XML or CSV File to WordPress <= 3.6.6 - Reflected Cross-Site Scripting | June 2, 2022 | 3.6.7 | Medium |
[*, 3.6.3) | Import any XML or CSV File to WordPress <= 3.6.2 - Authenticated Stored Cross-Site Scripting | November 2, 2021 | 3.6.3 | Medium |
*-3.2.4 | Import any XML or CSV File to WordPress <= 3.2.4 - Missing Authorization and Cross-Site Request Forgery Checks | February 19, 2020 | 3.2.5 | Medium |
*-3.2.4 | Import any XML or CSV File to WordPress <= 3.2.4 - SQL Injection | February 19, 2020 | 3.2.5 | High |
[*, 3.2.4) | Import any XML or CSV File to WordPress <= 3.2.3 & PRO < 4.1.1 - Missing Authorization Checks | August 20, 2019 | 3.2.4 | High |
[*, 3.4.7) | WP All Import <= 3.4.6 - Cross-Site Scripting | March 8, 2018 | 3.4.7 | Medium |
[*, 3.4.6) | WP All Import <= 3.4.5 - Cross-Site Scripting | March 8, 2018 | 3.4.6 | Medium |
[*, 3.4.7) | Import any XML or CSV File to WordPress <= 3.4.6 - Cross-Site Scripting | March 7, 2018 | 3.4.7 | Medium |
[*, 3.4.6) | Import any XML or CSV File to WordPress <= 3.4.5 - Cross-Site Scripting | October 8, 2017 | 3.4.6 | Medium |
[*, 3.2.5) | Import any XML or CSV File to WordPress < 3.2.5 - SQL Injection | March 12, 2015 | 3.2.5 | Critical |
*-3.2.4 | Import any XML or CSV File to WordPress <= 3.2.4 - Reflected Cross-Site Scripting | February 26, 2015 | 3.2.5 | Medium |
Selected source records
Published: June 26, 2026
Published: March 5, 2026
Published: November 12, 2025
Published: September 9, 2025
Published: April 7, 2025
Published: April 10, 2024
Published: December 29, 2023
Published: October 17, 2022
Published: March 12, 2015
Published: June 28, 2022
Published: November 12, 2025
Published: August 20, 2019
Published: December 29, 2023
Published: February 19, 2020
Published: June 30, 2022
Published: September 9, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.