Description
WordPress Plugin ImportWP-Import any XML or CSV File into WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete specified posts. WordPress Plugin ImportWP-Import any XML or CSV File into WordPress version 1.1.5 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Social Metrics Tracker Cross-Site Scripting (1.6.8)
PHP Resource Management Errors Vulnerability (CVE-2012-0781)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-6532)
WordPress Plugin AccessPress Social Icons SQL Injection (1.8.0)
WordPress Plugin Newsletter-Send awesome emails from WordPress Cross-Site Scripting (3.2.6)