References https://github.com/Nxploited/CVE-2025-4190 https://wpscan.com/vulnerability/e525ece5-6e03-4aee-bf5b-6ae0b961f027/ https://nvd.nist.gov/vuln/detail/CVE-2025-4190 https://www.cvedetails.com/cve/CVE-2025-4190/ https://hackhalt.com/threat/cve-2025-4190/ https://patchstack.com/database/wordpress/plugin/csv-mass-importer/vulnerability/wordpress-csv-mass-importer-plugin-1-2-admin-arbitrary-file-upload-vulnerability https://github.com/GadaLuBau1337/CVE-2025-4190 https://cve.imfht.com/detail/CVE-2025-4190 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/csv-mass-importer/csv-mass-importer-12-authenticated-admin-arbitrary-file-upload https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-4190
Related VulnerabilitiesphpVMS /importer 未授权访问漏洞(CVE-2026-42569)PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassPoCCVE-2024-12732: AffiliateImporterEb <= 1.0.6 - Reflected XSSERPNext /api/method/erpnext.accounts.doctype.chart_of_accounts_importer.chart_of_accounts_importer.import_coa SQL 注入漏洞(CVE-2025-52043)PoCwp-importer-log-disclosure: WordPress Importer - Error Log DisclosurePoCCVE-2015-2068: Magento Server Mass Importer - Cross-Site ScriptingPoCCVE-2020-36333: ThemeGrill Demo Importer < 1.6.2 - Database ResetPoCCVE-2020-5777: Magento Mass Importer <0.7.24 - Remote Auth BypassPoCaspose-ie-file-download: WordPress Aspose Importer & Exporter 1.0 - Local File InclusionWordPress plugin Etsy Importer 跨站脚本漏洞