Extension WordPress

Vulnérabilités Import and export users and customers

Cette page rassemble les failles publiées pour Import and export users and customers, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
0Critiques
24Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Import and export users and customers

24 fiches

CVE-2026-15026 Moyenne · 4,3
Import and export users and customers

Import and export users and customers <= 2.4.0 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and…

Versions affectées

*-2.4.0

Correctif

2.4.1

Publication

09/07/2026

CVE-2026-7641 Élevée · 8,8
Import and export users and customers

Import and export users and customers <= 2.0.8 – Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability…

Versions affectées

*-2.0.8

Correctif

2.0.9

Publication

01/05/2026

CVE-2026-3629 Élevée · 8,1
Import and export users and customers

Import and export users and customers <= 1.29.7 – Privilege Escalation to Administrator via save_extra_user_profile_fields

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can…

Versions affectées

*-1.29.7

Correctif

2.0

Publication

21/03/2026

CVE-2025-24689 Moyenne · 5,3
Import and export users and customers

Import and export users and customers <= 1.27.12 – Unauthenticated Sensitive Information Disclosure

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.27.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Versions affectées

*-1.27.12

Correctif

1.27.13

Publication

27/01/2025

CVE-2024-50413 Moyenne · 4,4
Import and export users and customers

Import and export users and customers <= 1.27.5 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-1.27.5

Correctif

1.27.6

Publication

24/10/2024

CVE-2024-38787 Moyenne · 5,3
Import and export users and customers

Import and export users and customers <= 1.26.8 – Unauthenticated Information Exposure

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.26.8 via the fileupload_process function that uploads an import file in a public directory and…

Versions affectées

*-1.26.8

Correctif

1.26.9

Publication

07/08/2024

CVE-2024-4734 Moyenne · 4,4
Import and export users and customers

Import and export users and customers <= 1.26.6.1 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.26.6.1

Correctif

1.26.7

Publication

14/05/2024

CVE-2024-4656 Moyenne · 4,4
Import and export users and customers

Import and export users and customers <= 1.26.6.1 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-1.26.6.1

Correctif

1.26.7

Publication

14/05/2024

CVE-2024-1050 Moyenne · 4,3
Import and export users and customers

Import and export users and customers <= 1.26.5 – Missing Authorization

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it…

Versions affectées

*-1.26.5

Correctif

1.26.6

Publication

03/05/2024

CVE-2024-32817 Élevée · 7,2
Import and export users and customers

Import and export users and customers <= 1.26.2 – Authenticated (Admin+) PHP Object Injection

The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.26.2 via deserialization of untrusted input in the import.php file. This makes it possible for…

Versions affectées

*-1.26.2

Correctif

1.26.3

Publication

22/04/2024

CVE-2024-22151 Moyenne · 5,3
Import and export users and customers

Import and export users and customers <= 1.24.6 – Missing Authorization via fire_cron REST endpoint

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the fire_cron function in versions up to, and including, 1.24.6. This makes it possible…

Versions affectées

*-1.24.6

Correctif

1.24.7

Publication

16/01/2024

CVE-2023-6624 Moyenne · 4,9
Import and export users and customers

Import and export users and customers <= 1.24.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-1.24.3

Correctif

1.24.4

Publication

11/12/2023

CVE-2023-6583 Moyenne · 6,6
Import and export users and customers

Import and export users and customers <= 1.24.2 – Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access…

Versions affectées

*-1.24.2

Correctif

1.24.3

Publication

08/12/2023

CVE-2022-3558 Élevée · 8,0
Import and export users and customers

Import and export users and customers <= 1.20.4 – Authenticated (Subscriber+) CSV Injection

The Import and export users and customers plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.20.4. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in…

Versions affectées

*-1.20.4

Correctif

1.20.5

Publication

17/10/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités