CVE-2018-16254 (wp_all_import)

There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options.
Source: NIST
CVE-2018-16254 (wp_all_import)