PT-2025-37005 · WordPress · Import Any Xml

Nguyen Quang Truong

+2

·

Published

2025-09-10

·

Updated

2025-09-15

·

CVE-2025-10001

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Import any XML, CSV or Excel File to WordPress plugin versions through 3.9.3
Description: The Import any XML, CSV or Excel File to WordPress plugin for WordPress is susceptible to arbitrary file uploads due to the absence of file type validation during the import process. This allows authenticated attackers with Administrator-level access or higher to upload potentially harmful files, such as .phar files, to the server. Successful exploitation may lead to remote code execution.
Recommendations: Update to a version beyond 3.9.3.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10001

Affected Products

Import Any Xml