Extension WordPress
Vulnérabilités Export and Import Users and Customers
Cette page rassemble les failles publiées pour Export and Import Users and Customers, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Export and Import Users and Customers
10 fiches
Export and Import Users and Customers <= 2.6.2 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and…
*-2.6.2
2.6.3
22/03/2025
Export and Import Users and Customers <= 2.6.2 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible…
*-2.6.2
2.6.3
22/03/2025
Export and Import Users and Customers <= 2.6.2 – Authenticated (Admin+) PHP Object Injection via form_data Parameter
The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for…
*-2.6.2
2.6.3
22/03/2025
Export and Import Users and Customers <= 2.6.2 – Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access…
*-2.6.2
2.6.3
22/03/2025
Export and Import Users and Customers <= 2.5.3 – Authenticated (Admin+) PHP Object Injection
The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.3 via deserialization of untrusted input in the import.php file. This makes it possible for…
*-2.5.3
2.5.4
22/04/2024
Import Export WordPress Users <= 2.5.2 – Authenticated (Shop Manager+) Path Traversal
The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with shop manager-level access and above, to read…
*-2.5.2
2.5.3
28/03/2024
Export and Import Users and Customers <= 2.4.8 – Authenticated (Shop Manager+) Arbitrary File Upload
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for…
*-2.4.8
2.4.9
12/12/2023
Export and Import Users and Customers <= 2.4.1 – Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change
The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including,…
*-2.4.1
2.4.2
14/07/2023
WebToffee Plugins <= (Various Versions) – Arbitrary User Creation
The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
[*, 1.3.9)
1.3.9
11/03/2020
Import Export WordPress Users and WooCommerce Customers <= 1.3.1 – CSV Injection
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.1 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.
[*, 1.3.2)
1.3.2
22/08/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.