Description
WordPress Plugin Import all XML, CSV & TXT into WordPress is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information (usernames, hashed passwords and email addresses) that may help in launching further attacks. WordPress Plugin Import all XML, CSV & TXT into WordPress version 3.6.74 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 3.6.75 or latest
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2005-1383)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2022-1434)
WordPress Plugin is_human() 'type' Parameter Remote Command Injection (1.4.2)
MySQL CVE-2017-3459 Vulnerability (CVE-2017-3459)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (1.2.05.20)