Lucene search

K

Import Export Wordpress Users Security Vulnerabilities

cve
cve

CVE-2019-15092

The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.

7.3CVSS

7.3AI Score

0.001EPSS

2019-08-23 09:15 PM
136
cve
cve

CVE-2020-12074

The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.

8.8CVSS

8.7AI Score

0.001EPSS

2020-04-23 02:15 AM
116
cve
cve

CVE-2023-3459

The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attack...

7.2CVSS

6.8AI Score

0.001EPSS

2023-07-18 03:15 AM
27
cve
cve

CVE-2023-6558

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level ca...

7.2CVSS

7.4AI Score

0.001EPSS

2024-01-11 09:15 AM
13