cleantalk
Vulnerabilities and Security Researches

Import any XML or CSV File to WordPress, 23f0deb78bcc3ed57c0cb3b303981074d5af4d43

Published on
Feb 26, 2015
Research Description
WP All Import – Drag &amp; Drop Import for CSV, XML, Excel &amp; Google Sheets [wp-all-import] < 3.2.4 WordPress WP All Import Plugin <= 3.2.3 - Remote Code Execution Because of this vulnerability, remote attackers can upload arbitrary files to system or retrieve any files on the system that ends in .txt or .html. Update the plugin.
Affected versions
max 3.2.4.
Status
vulnerable