Known vulnerabilities in Import WP – Export and Import CSV and XML files to WordPress
Import WP, a simple, fast and powerful XML and CSV import solution, Making it easy to import posts, pages, categories, tags, users and attachments.
3Reported vulnerabilities
5.3Highest CVSS score
2.14.23Latest version
4,000+Active installs
What to do now
Update Import WP – Export and Import CSV and XML files to WordPress to 2.14.23 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-14925 | Medium | 0.3% | Before 2.14.23 | 2.14.23 |
August 14, 2026 |
| CVE-2025-12894 | Medium | 0.3% | 2.14.17 and earlier | 2.14.18 |
November 20, 2025 |
| CVE-2025-12137 | Medium | 0.4% | 0 to 2.14.16 (inclusive) | 2.14.17 |
November 1, 2025 |