Import and Export Users and Customers
Codection · 8 CVEs
WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability
Aug 13, 2024
WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability
Jun 11, 2024
WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability
Jun 8, 2024
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
May 15, 2024
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Impor…
Jan 11, 2024
Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Jan 11, 2024
Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection
Nov 7, 2022
Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting
May 2, 2022
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
Nov 4, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-38787 | WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability | HIGH | 0.42% | Aug 13, 2024 |
| CVE-2024-34815 | WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability | MEDIUM | 0.37% | Jun 11, 2024 |
| CVE-2024-22151 | WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability | MEDIUM | 0.32% | Jun 8, 2024 |
| CVE-2024-4734 | Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting | MEDIUM | 0.29% | May 15, 2024 |
| CVE-2023-6583 | Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality | HIGH | 0.80% | Jan 11, 2024 |
| CVE-2023-6624 | Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode | MEDIUM | 0.35% | Jan 11, 2024 |
| CVE-2022-3558 | Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection | HIGH | 1.09% | Nov 7, 2022 |
| CVE-2022-1255 | Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting | MEDIUM | 0.71% | May 2, 2022 |
| CVE-2020-22277 | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. | HIGH | 1.85% | Nov 4, 2020 |
Showing 1 to 8 of 8 CVEs