Description
WordPress Plugin ImportWP-Import any XML or CSV File into WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete specified posts. WordPress Plugin ImportWP-Import any XML or CSV File into WordPress version 1.1.5 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
Rukovoditel Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-11815)
MySQL CVE-2014-6494 Vulnerability (CVE-2014-6494)
WordPress Plugin Rucy Cross-Site Request Forgery (0.4.4)
WordPress Plugin WP CSV Exporter SQL Injection (1.3.6)
WordPress Plugin WordPress Books Gallery Cross-Site Request Forgery (4.4.8)