Remote Code Execution Vulnerability in WP All Import Plugin for WordPress
CVE-2025-12733
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 November 2025
What is CVE-2025-12733?
The WP All Import plugin for WordPress is susceptible to Remote Code Execution due to improper handling of user-supplied input within the pmxi_if function found in helpers/functions.php. This vulnerability allows authenticated users with import capabilities, notably administrators, to exploit the improper use of the eval() function. By crafting malicious import templates, attackers can inject and execute arbitrary PHP code on the server, potentially compromising the entire WordPress installation. It is crucial for users to update to the latest version or apply necessary security measures to mitigate this risk.
Affected Version(s)
Import any XML, CSV or Excel File to WordPress * <= 3.9.6