PLUGIN SECURITY

Is Wp All Import safe?

Easily import any file of any size into any plugin, post type, custom field, or taxonomy. Supports WooCommerce, ACF, images, galleries, users, real es …

What this plugin does

  • Slug: wp-all-import
  • Author: WP All Import
  • 100000+ active installs
  • 94/100 rating (1962 reviews on wordpress.org)
  • 5537574 all-time downloads
  • On WordPress.org since 2012-07-24

csvdatafeedwordpress csv importwordpress xml importxml

Maintenance status

  • Latest known version: 4.1.1
  • Last updated: 2026-07-16 2:00am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

26 known CVEs on file for Wp All Import.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57628 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.1.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 4.1.0 4.1.0 2026-06-26 ✓ fixed in latest
CVE-2025-12733 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.0.0 Improper Control of Generation of Code ('Code Injection') High 8.8 < 4.0.0 4.0.0 2025-11-12 ✓ fixed in latest
CVE-2025-10001 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.9.4 Unrestricted Upload of File with Dangerous Type High 7.2 < 3.9.4 3.9.4 2025-09-09 ✓ fixed in latest
CVE-2024-31939 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.7.4 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.7.4 3.7.4 2024-04-10 ✓ fixed in latest
CVE-2023-7082 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.7.3 Unrestricted Upload of File with Dangerous Type High 7.2 < 3.7.3 3.7.3 2023-12-29 ✓ fixed in latest
CVE-2022-3418 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.9 Improper Control of Generation of Code ('Code Injection') High 7.2 < 3.6.9 3.6.9 2022-10-17 ✓ fixed in latest
CVE-2022-2711 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.9 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.2 < 3.6.9 3.6.9 2022-10-17 ✓ fixed in latest
CVE-2022-2268 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 Unrestricted Upload of File with Dangerous Type High 7.2 < 3.6.8 3.6.8 2022-07-01 ✓ fixed in latest
+ 28 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-1565 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 Unrestricted Upload of File with Dangerous Type High 7.2 < 3.6.8 3.6.8 2022-06-30 ✓ fixed in latest
CVE-2022-36386 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.8 Improper Control of Generation of Code ('Code Injection') Critical 9.1 < 3.6.8 3.6.8 2022-06-28 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.7 Unknown < 3.6.7 3.6.7 2022-06-02 ✓ fixed in latest
CVE-2021-24714 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.6.3 3.6.3 2021-11-02 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Unknown < 3.2.5 3.2.5 2020-02-19 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Unknown < 3.2.5 3.2.5 2020-02-19 ✓ fixed in latest
CVE-2015-9331 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.4 High 7.5 < 3.2.4 3.2.4 2019-08-20 ✓ fixed in latest
CVE-2018-16257 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.9 3.4.9 2019-04-12 ✓ fixed in latest
CVE-2018-16255 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.9 3.4.9 2019-04-12 ✓ fixed in latest
CVE-2018-16254 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.9 3.4.9 2019-04-12 ✓ fixed in latest
CVE-2018-16256 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.9 3.4.9 2019-04-12 ✓ fixed in latest
CVE-2018-16258 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.9 3.4.9 2019-04-12 ✓ fixed in latest
CVE-2018-16259 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] <= 3.4.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.9 3.4.9 2019-04-12 ✓ fixed in latest
CVE-2018-0546 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.6 3.4.6 2018-03-08 ✓ fixed in latest
CVE-2018-0547, CVE-2018-20978 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.7 3.4.7 2018-03-08 ✓ fixed in latest
CVE-2018-20978 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.7 3.4.7 2018-03-07 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.6 Unknown < 3.4.6 3.4.6 2017-10-17 ✓ fixed in latest
CVE-2017-18567 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.4.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.4.6 3.4.6 2017-10-08 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Unknown < 3.2.5 3.2.5 2015-03-17 ✓ fixed in latest
CVE-2015-9330 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.2.5 3.2.5 2015-03-12 ✓ fixed in latest
CVE-2015-9329, CVE-2015-9330 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.2.5 3.2.5 2015-02-26 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.2.4 Unknown < 3.2.4 3.2.4 2015-02-26 ✓ fixed in latest
CVE-2014-2054 WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.9.0 Unknown < 3.9.0 3.9.0 2014-06-04 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.8.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.8.0 3.8.0 0000-00-00 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.0.1 Unknown < 4.0.1 4.0.1 0000-00-00 ✓ fixed in latest
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.6.5 Unknown < 3.6.5 3.6.5 ✓ fixed in latest
WP All Import < 3.6.5 - Reflected Cross-Site Scripting Unknown < 3.6.5 3.6.5 ✓ fixed in latest
CVE-2026-2830 WP All Import < 4.0.1 - Reflected Cross-Site Scripting via 'filepath' Unknown < 4.0.1 4.0.1 ✓ fixed in latest

How to fix it

Keep Wp All Import updated — 4.1.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.