
CVE-2026-2830 The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ param… https://www.cve.org/CVERecord?id=CVE-2026-2830
Post summary
This post announces CVE‑2026‑2830, detailing a reflected XSS flaw in the WP All Import plugin triggered via the ‘filepath’ parameter. No exploitation evidence or patch information is provided.

