CVE Database /
CVE-2014-2054
CVE
CVE-2014-2054 — WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.9.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2014-2054
|
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.9.0 |
— |
Unknown
|
< 3.9.0
|
3.9.0 |
2014-06-04 |
—
|
CVE-2014-2054
The WP All Import plugin before version 3.9.0 contains a vulnerability in its use of PHPExcel library, where external entity loading is not properly disabled in libxml. This flaw allows attackers to conduct XML External Entity attacks, potentially enabling them to read arbitrary files from the server or trigger denial of service conditions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings