WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Wp All Import?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Wp All Import — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: wp-all-import
  • 100000+ instalaciones activas

csvdatafeedwordpress csv importwordpress xml importxml

Estado de mantenimiento

  • Última versión conocida: 4.1.1
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): <8.0

Vulnerabilidades conocidas

27 CVEs conocidos registrados para Wp All Import.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-57628 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.1.0 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,6 < 4.1.0 4.1.0 2026-06-26 ✓ corregido en la última versión
CVE-2025-12733 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.0.0 Control incorrecto de la generación de código (inyección de código) Alta 8,8 < 4.0.0 4.0.0 2025-11-12 ✓ corregido en la última versión
CVE-2025-10001 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.9.4 Carga de archivos sin restricción de tipo peligroso Alta 7,2 < 3.9.4 3.9.4 2025-09-09 ✓ corregido en la última versión
CVE-2024-31939 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.7.4 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.7.4 3.7.4 2024-04-10 ✓ corregido en la última versión
CVE-2023-7082 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.7.3 Carga de archivos sin restricción de tipo peligroso Alta 7,2 < 3.7.3 3.7.3 2023-12-29 ✓ corregido en la última versión
CVE-2022-3418 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.9 Control incorrecto de la generación de código (inyección de código) Alta 7,2 < 3.6.9 3.6.9 2022-10-17 ✓ corregido en la última versión
CVE-2022-2711 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.9 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 7,2 < 3.6.9 3.6.9 2022-10-17 ✓ corregido en la última versión
CVE-2022-2268 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 Carga de archivos sin restricción de tipo peligroso Alta 7,2 < 3.6.8 3.6.8 2022-07-01 ✓ corregido en la última versión

CVE-2026-57628

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-12733

The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval() on unsanitized user-supplied input in the pmxi_if function within helpers/functions.php. This makes it possible for authenticated attackers, with import capabilities (typically administrators), to inject and execute arbitrary PHP code on the server via crafted import templates. This can lead to remote code execution.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-10001

The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload unsafe files like .phar files on the affected site's server which may make remote code execution possible.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-31939

Update the WordPress Import any XML or CSV File to WordPress plugin to the latest available version (at least 3.7.4). Dhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Import any XML or CSV File to WordPress Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.7.4. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-7082

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload functionality in all versions up to, and including, 3.7.2 . This makes it possible for authenticated attackers with admin-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-3418

Update the WordPress Import any XML or CSV File to WordPress plugin to the latest available version (at least 3.6.9). lucy discovered and reported this Arbitrary File Upload vulnerability in WordPress Import any XML or CSV File to WordPress Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 3.6.9.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-2711

Update the WordPress Import any XML or CSV File to WordPress plugin to the latest available version (at least 3.6.9). lucy discovered and reported this Directory Traversal vulnerability in WordPress Import any XML or CSV File to WordPress Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 3.6.9.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-2268

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 26 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2022-1565 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 Carga de archivos sin restricción de tipo peligroso Alta 7,2 < 3.6.8 3.6.8 2022-06-30 ✓ corregido en la última versión
CVE-2022-36386 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 Control incorrecto de la generación de código (inyección de código) Crítica 9,1 < 3.6.8 3.6.8 2022-06-28 ✓ corregido en la última versión
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.7 Desconocido < 3.6.7 3.6.7 2022-06-02 ✓ corregido en la última versión
CVE-2021-24714 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.6.3 3.6.3 2021-11-02 ✓ corregido en la última versión
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Desconocido < 3.2.5 3.2.5 2020-02-19 ✓ corregido en la última versión
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Desconocido < 3.2.5 3.2.5 2020-02-19 ✓ corregido en la última versión
CVE-2015-9331 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.4 Alta 7,5 < 3.2.4 3.2.4 2019-08-20 ✓ corregido en la última versión
CVE-2018-16257 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.9 3.4.9 2019-04-12 ✓ corregido en la última versión
CVE-2018-16255 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.9 3.4.9 2019-04-12 ✓ corregido en la última versión
CVE-2018-16254 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.9 3.4.9 2019-04-12 ✓ corregido en la última versión
CVE-2018-16256 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.9 3.4.9 2019-04-12 ✓ corregido en la última versión
CVE-2018-16258 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.9 3.4.9 2019-04-12 ✓ corregido en la última versión
CVE-2018-16259 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.9 3.4.9 2019-04-12 ✓ corregido en la última versión
CVE-2018-0546 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.6 3.4.6 2018-03-08 ✓ corregido en la última versión
CVE-2018-0547 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.7 3.4.7 2018-03-08 ✓ corregido en la última versión
CVE-2018-20978 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.7 3.4.7 2018-03-07 ✓ corregido en la última versión
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.6 Desconocido < 3.4.6 3.4.6 2017-10-17 ✓ corregido en la última versión
CVE-2017-18567 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.4.6 3.4.6 2017-10-08 ✓ corregido en la última versión
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Desconocido < 3.2.5 3.2.5 2015-03-17 ✓ corregido en la última versión
CVE-2015-9330 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Crítica 9,8 < 3.2.5 3.2.5 2015-03-12 ✓ corregido en la última versión
CVE-2015-9329 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.2.5 3.2.5 2015-02-26 ✓ corregido en la última versión
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.4 Desconocido < 3.2.4 3.2.4 2015-02-26 ✓ corregido en la última versión
CVE-2014-2054 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.9.0 Desconocido < 3.9.0 3.9.0 2014-06-04 ✓ corregido en la última versión
CVE-2024-9661 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.8.0 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.8.0 3.8.0 0000-00-00 ✓ corregido en la última versión
CVE-2026-2830 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.0.1 Desconocido < 4.0.1 4.0.1 0000-00-00 ✓ corregido en la última versión
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.5 Desconocido < 3.6.5 3.6.5 ✓ corregido en la última versión

CVE-2022-1565

The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-36386

Update the WordPress Import any XML or CSV File to WordPress plugin to the latest available version (at least 3.6.8). Universe discovered and reported this Arbitrary Code Execution vulnerability in WordPress Import any XML or CSV File to WordPress Plugin. This could allow a malicious actor to remotely execute malicious code on your site. This code could take-over your entire website or create more backdoors and inject advertisements. This vulnerability has been fixed in version 3.6.8.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.7

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg| without appropriate escaping on the URL in versions up to, and including, 3.6.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-24714

The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative capabilities and above to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.2.4 due to missing capability and nonce checks on various functions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2015-9331

WP All Import does not properly verify that a user has permission to execute functions. Coupled with an interesting method that allows arbitrary functions in specific objects to be called allows this to be leveraged in many ways.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2018-16257

There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-16255

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-16254

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-16256

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-16258

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-16259

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-0546

The WordPress plugin "WP All Import" provided by Soflyy contains a cross-site scripting vulnerability (CWE-79) in the file upload function. Note that this vulnerability is different from JVN#60032768. Mardan Muhidin of Gehirn Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

CVE-2018-0547

The WordPress plugin "WP All Import" provided by Soflyy contains a reflected cross-site scripting vulnerability (CWE-79). Note that this vulnerability is different from JVN#33527174. Yuji Tounai of NTT Communications Corporation reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

CVE-2018-20978

The wp-all-import plugin before 3.4.7 for WordPress has XSS.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.6

Cross-Site Scripting (XSS) vulnerability found in WordPress Import any XML or CSV File to WordPress plugin (versions <=3.4.5).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2017-18567

The Import any XML or CSV File to WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5

This plugin is prone to an SQL injection and cross site scripting vulnerabilities. Because of them, attackers can gain admin access to your website or trick you into visiting the malicious URL. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2015-9330

Multiple issues were fixed, such as Authenticated SQL Injection, Authenticated Reflected XSS and Unauthorised access to some methods

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2015-9329

The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.4

Because of this vulnerability, remote attackers can upload arbitrary files to system or retrieve any files on the system that ends in .txt or .html. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2014-2054

PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-9661

<p>WordPress WP All Import Plugin <= 3.7.9 is vulnerable to Cross Site Request Forgery (CSRF)</p><p>Software: WP All Import</p><p>Fixed in version 3.8.0 </p><p>Affected Version <= 3.7.9</p><p>CVE: CVE-2024-9661</p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2026-2830

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.5

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Wp All Import actualizado — 4.1.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.