Extension WordPress

Vulnérabilités Export and Import Users and Customers

Cette page rassemble les failles publiées pour Export and Import Users and Customers, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
0Critiques
10Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Export and Import Users and Customers

10 fiches

CVE-2025-1973 Moyenne · 4,9
Export and Import Users and Customers

Export and Import Users and Customers <= 2.6.2 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and…

Versions affectées

*-2.6.2

Correctif

2.6.3

Publication

22/03/2025

CVE-2025-1972 Faible · 2,7
Export and Import Users and Customers

Export and Import Users and Customers <= 2.6.2 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible…

Versions affectées

*-2.6.2

Correctif

2.6.3

Publication

22/03/2025

CVE-2025-1971 Élevée · 7,2
Export and Import Users and Customers

Export and Import Users and Customers <= 2.6.2 – Authenticated (Admin+) PHP Object Injection via form_data Parameter

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for…

Versions affectées

*-2.6.2

Correctif

2.6.3

Publication

22/03/2025

CVE-2025-1970 Élevée · 7,6
Export and Import Users and Customers

Export and Import Users and Customers <= 2.6.2 – Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access…

Versions affectées

*-2.6.2

Correctif

2.6.3

Publication

22/03/2025

CVE-2023-6558 Élevée · 7,2
Export and Import Users and Customers

Export and Import Users and Customers <= 2.4.8 – Authenticated (Shop Manager+) Arbitrary File Upload

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for…

Versions affectées

*-2.4.8

Correctif

2.4.9

Publication

12/12/2023

CVE-2023-3459 Élevée · 7,2
Export and Import Users and Customers

Export and Import Users and Customers <= 2.4.1 – Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change

The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including,…

Versions affectées

*-2.4.1

Correctif

2.4.2

Publication

14/07/2023

CVE-2019-15092 Élevée · 7,3
Export and Import Users and Customers

Import Export WordPress Users and WooCommerce Customers <= 1.3.1 – CSV Injection

The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.1 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.

Versions affectées

[*, 1.3.2)

Correctif

1.3.2

Publication

22/08/2018

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités