There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type.
Published April 12, 2019.
Soflyy WP All Import