← Back to CVE List

CVE-2018-16254

Published: 2019-04-12T18:29Z
Last Modified: 2024-11-21T03:52Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator > MITRE Terms of Use apply – see LICENSE‑MITRE.txt