Extension WordPress
Vulnérabilités Import and export users and customers
Cette page rassemble les failles publiées pour Import and export users and customers, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Import and export users and customers
24 fiches
Import and export users and customers <= 2.4.0 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and…
*-2.4.0
2.4.1
09/07/2026
Import and export users and customers <= 2.0.8 – Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability…
*-2.0.8
2.0.9
01/05/2026
Import and export users and customers <= 1.29.7 – Privilege Escalation to Administrator via save_extra_user_profile_fields
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can…
*-1.29.7
2.0
21/03/2026
Import and export users and customers <= 1.27.12 – Unauthenticated Sensitive Information Disclosure
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.27.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-1.27.12
1.27.13
27/01/2025
Import and export users and customers <= 1.27.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.27.5
1.27.6
24/10/2024
Import and export users and customers <= 1.26.8 – Unauthenticated Information Exposure
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.26.8 via the fileupload_process function that uploads an import file in a public directory and…
*-1.26.8
1.26.9
07/08/2024
Import and export users and customers <= 1.26.6.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it…
*-1.26.6.1
1.26.7
14/05/2024
Import and export users and customers <= 1.26.6.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This…
*-1.26.6.1
1.26.7
14/05/2024
Import and export users and customers <= 1.26.5 – Missing Authorization
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.26.5. This makes it possible for authenticated attackers,…
*-1.26.5
1.26.6
09/05/2024
Import and export users and customers <= 1.26.5 – Missing Authorization
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it…
*-1.26.5
1.26.6
03/05/2024
Import and export users and customers <= 1.26.2 – Authenticated (Admin+) PHP Object Injection
The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.26.2 via deserialization of untrusted input in the import.php file. This makes it possible for…
*-1.26.2
1.26.3
22/04/2024
Import and export users and customers <= 1.24.6 – Missing Authorization via fire_cron REST endpoint
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the fire_cron function in versions up to, and including, 1.24.6. This makes it possible…
*-1.24.6
1.24.7
16/01/2024
Import and export users and customers <= 1.24.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user…
*-1.24.3
1.24.4
11/12/2023
Import and export users and customers <= 1.24.2 – Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access…
*-1.24.2
1.24.3
08/12/2023
Import and export users and customers <= 1.20.4 – Authenticated (Subscriber+) CSV Injection
The Import and export users and customers plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.20.4. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in…
*-1.20.4
1.20.5
17/10/2022
Import and export users and customers <= 1.19.2 – Stored Cross-Site Scripting
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitize and escape imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues
[*, 1.19.2.1)
1.19.2.1
11/04/2022
Import and export users and customers <= 1.16.3.5 – CSV injection via a customer's profile
Import and export users and customers WordPress Plugin through 1.16.3.5 allows CSV injection via a customer's profile.
*-1.16.3.5
1.16.3.6
20/11/2020
Import and export users and customers 1.15 – Sensitive Data Exposure
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 via the export_users_csv function. This can allow authenticated attackers to export user information even if they do not have…
1.15
1.15.0.1
01/01/2020
Import and export users and customers <= 1.14.1.3 – Cross-Site Request Forgery leading to attachment deletion & Path Traversal
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
*-1.14.1.3
1.14.2.2
22/06/2019
Import and export users and customers <= 1.14.1.2 – Cross-Site Scripting
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
*-1.14.1.2
1.14.1.3
20/06/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.