Description
WordPress Plugin Import all XML, CSV & TXT into WordPress is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin Import all XML, CSV & TXT into WordPress version 6.5.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.5.3 or latest
References
Related Vulnerabilities
WordPress Plugin WP Job Manager Privilege Escalation (1.34.4)
WordPress Plugin CiviCRM Security Bypass (5.35.1)
WordPress 4.7.x Prototype Pollution (4.7 - 4.7.22)
Telerik Web UI Missing Authorization Vulnerability (CVE-2021-28141)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2402)