cleantalk
Vulnerabilities and Security Researches

Import any XML or CSV File to WordPress, e5cae750-cf85-4978-b2e7-5b37ec97766e

Published on
-
Research Description
WP All Import – Drag &amp; Drop Import for CSV, XML, Excel &amp; Google Sheets [wp-all-import] < 3.6.5 WP All Import &lt; 3.6.5 - Reflected Cross-Site Scripting The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Affected versions
max 3.6.5.
Status
vulnerable