MEDIUM
WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability
Published Jun 8, 2024
5.3
MEDIUMCVSS 3.1
EPSS 0.32%
Description
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
Affected products
-
- Version -StatusaffectedConstraints<=1.24.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Codection | Import and export users and customers | unaffected |
|
- < 1.24.7
-
- Version 0StatusaffectedConstraints<=1.24.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Codection | Import and Export Users and Customers | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 1.24.7 or a higher version.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-19747 Advisory
- https://patchstack.com/database/vulnerability/import-users-from-csv-with-meta/wordpress-import-and-export-users-and-customers-plugin-1-24-6-broken-access-control-vulnerability?_s_id=cve vdb-entryThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Jun 8, 2024
Updated Apr 28, 2026
Reserved Jan 5, 2024
Link CVE-2024-22151
CISA Vulnrichment
Updated Jun 10, 2024
ENISA EUVD
EUVD-2024-19747 Assigner Patchstack
Published Jun 8, 2024
Updated Apr 28, 2026
Exploited since n/a
Link EUVD-2024-19747