Reflected Cross-Site Scripting in WP All Import Plugin for WordPress
CVE-2026-2830
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 March 2026
What is CVE-2026-2830?
The WP All Import plugin for WordPress is susceptible to a Reflected Cross-Site Scripting vulnerability through the 'filepath' parameter. This issue arises from inadequate input sanitization and output escaping across all versions up to and including 4.0.0. Attackers without authentication can exploit this vulnerability to inject arbitrary web scripts. If users unknowingly click a specially crafted link, it could result in the execution of malicious scripts on their browsers, posing a significant security risk.
Affected Version(s)
WP All Import β Drag & Drop Import for CSV, XML, Excel & Google Sheets 0 <= 4.0.0