Import and export users and customers < 2.4.3 - Authenticated (Admin+) Arbitrary File Read
medium
The Import and export users and customers plugin for WordPress is vulnerable to Path Traversal in all versions up to 2.4.3 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive inform...
- CVSS:
- 4.9
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Jul 24, 2026
CVE-2025-15673 on NVD →
Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action
medium
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_c...
- CVSS:
- 4.3
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 9, 2026
CVE-2026-15026 on NVD →
Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields
high
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g., `wp_capabil...
- CVSS:
- 8.8
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- May 1, 2026
CVE-2026-7641 on NVD →
Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields
high
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' met...
- CVSS:
- 8.1
- Affected:
- up to 1.29.7
- Fixed in:
- 2.0
- Disclosed:
- Mar 21, 2026
CVE-2026-3629 on NVD →
Import and export users and customers <= 1.27.12 - Unauthenticated Sensitive Information Disclosure
medium
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.27.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.27.12
- Fixed in:
- 1.27.13
- Disclosed:
- Jan 27, 2025
CVE-2025-24689 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.27.13
unknown
[en] Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue affects Import and export users and customers: from n/a through 1.27.12.
- Affected:
- up to 1.27.13
- Fixed in:
- 1.27.13
- Disclosed:
- Jan 27, 2025
CVE-2025-24689 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.27.6
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codection Import and export users and customers allows Stored XSS.This issue affects Import and export users and customers: from n/a through 1.27.5.
- Affected:
- up to 1.27.6
- Fixed in:
- 1.27.6
- Disclosed:
- Oct 29, 2024
CVE-2024-50413 on NVD →
Import and export users and customers <= 1.27.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitr...
- CVSS:
- 4.4
- Affected:
- up to 1.27.5
- Fixed in:
- 1.27.6
- Disclosed:
- Oct 24, 2024
CVE-2024-50413 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.26.9
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
- Affected:
- up to 1.26.9
- Fixed in:
- 1.26.9
- Disclosed:
- Aug 13, 2024
CVE-2024-38787 on NVD →
Import and export users and customers <= 1.26.8 - Unauthenticated Information Exposure
medium
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.26.8 via the fileupload_process function that uploads an import file in a public directory and does not subsequently delete it. This makes it possible for unauthenticate...
- CVSS:
- 5.3
- Affected:
- up to 1.26.8
- Fixed in:
- 1.26.9
- Disclosed:
- Aug 7, 2024
CVE-2024-38787 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.26.6
unknown
[en] Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.5.
- Affected:
- up to 1.26.6
- Fixed in:
- 1.26.6
- Disclosed:
- Jun 11, 2024
CVE-2024-34815 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.24.7
unknown
[en] Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
- Affected:
- up to 1.24.7
- Fixed in:
- 1.24.7
- Disclosed:
- Jun 8, 2024
CVE-2024-22151 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.26.7
unknown
[en] The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator acc...
- Affected:
- up to 1.26.7
- Fixed in:
- 1.26.7
- Disclosed:
- May 15, 2024
CVE-2024-4656 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.26.7
unknown
[en] The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm...
- Affected:
- up to 1.26.7
- Fixed in:
- 1.26.7
- Disclosed:
- May 15, 2024
CVE-2024-4734 on NVD →
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...
- CVSS:
- 4.4
- Affected:
- up to 1.26.6.1
- Fixed in:
- 1.26.7
- Disclosed:
- May 14, 2024
CVE-2024-4734 on NVD →
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access a...
- CVSS:
- 4.4
- Affected:
- up to 1.26.6.1
- Fixed in:
- 1.26.7
- Disclosed:
- May 14, 2024
CVE-2024-4656 on NVD →
Import and export users and customers <= 1.26.5 - Missing Authorization
medium
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.26.5
- Fixed in:
- 1.26.6
- Disclosed:
- May 9, 2024
CVE-2024-34815 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.26.6
unknown
[en] The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscri...
- Affected:
- up to 1.26.6
- Fixed in:
- 1.26.6
- Disclosed:
- May 4, 2024
CVE-2024-1050 on NVD →
Import and export users and customers <= 1.26.5 - Missing Authorization
medium
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-l...
- CVSS:
- 4.3
- Affected:
- up to 1.26.5
- Fixed in:
- 1.26.6
- Disclosed:
- May 3, 2024
CVE-2024-1050 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.26.3
unknown
[en] Deserialization of Untrusted Data vulnerability in Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.2.
- Affected:
- up to 1.26.3
- Fixed in:
- 1.26.3
- Disclosed:
- Apr 24, 2024
CVE-2024-32817 on NVD →
Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object Injection
high
The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.26.2 via deserialization of untrusted input in the import.php file. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP...
- CVSS:
- 7.2
- Affected:
- up to 1.26.2
- Fixed in:
- 1.26.3
- Disclosed:
- Apr 22, 2024
CVE-2024-32817 on NVD →
Import and export users and customers <= 1.24.6 - Missing Authorization via fire_cron REST endpoint
medium
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the fire_cron function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to trigger the plugin's cron job.
- CVSS:
- 5.3
- Affected:
- up to 1.24.6
- Fixed in:
- 1.24.7
- Disclosed:
- Jan 16, 2024
CVE-2024-22151 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.24.4
unknown
[en] The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- Affected:
- up to 1.24.4
- Fixed in:
- 1.24.4
- Disclosed:
- Jan 11, 2024
CVE-2023-6624 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.24.3
unknown
[en] The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitr...
- Affected:
- up to 1.24.3
- Fixed in:
- 1.24.3
- Disclosed:
- Jan 11, 2024
CVE-2023-6583 on NVD →
Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...
- CVSS:
- 4.9
- Affected:
- up to 1.24.3
- Fixed in:
- 1.24.4
- Disclosed:
- Dec 11, 2023
CVE-2023-6624 on NVD →
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality
medium
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary f...
- CVSS:
- 6.6
- Affected:
- up to 1.24.2
- Fixed in:
- 1.24.3
- Disclosed:
- Dec 8, 2023
CVE-2023-6583 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.20.5
unknown
[en] The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
- Affected:
- up to 1.20.5
- Fixed in:
- 1.20.5
- Disclosed:
- Nov 7, 2022
CVE-2022-3558 on NVD →
Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV Injection
high
The Import and export users and customers plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.20.4. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system...
- CVSS:
- 8
- Affected:
- up to 1.20.4
- Fixed in:
- 1.20.5
- Disclosed:
- Oct 17, 2022
CVE-2022-3558 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.19.2.1
unknown
[en] The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues
- Affected:
- up to 1.19.2.1
- Fixed in:
- 1.19.2.1
- Disclosed:
- May 2, 2022
CVE-2022-1255 on NVD →
Import and export users and customers <= 1.19.2 - Stored Cross-Site Scripting
medium
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitize and escape imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues
- CVSS:
- 5.5
- Affected:
- up to 1.19.2.1
- Fixed in:
- 1.19.2.1
- Disclosed:
- Apr 11, 2022
CVE-2022-1255 on NVD →
Import and export users and customers <= 1.16.3.5 - CSV injection via a customer's profile
high
Import and export users and customers WordPress Plugin through 1.16.3.5 allows CSV injection via a customer's profile.
- CVSS:
- 7.3
- Affected:
- up to 1.16.3.5
- Fixed in:
- 1.16.3.6
- Disclosed:
- Nov 20, 2020
CVE-2020-22277 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.16.3.6
unknown
[en] Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
- Affected:
- up to 1.16.3.6
- Fixed in:
- 1.16.3.6
- Disclosed:
- Nov 4, 2020
CVE-2020-22277 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.15.0.1
unknown
Unauthorised Authenticated Users Export vulnerability found in WordPress Import Users From CSV with Meta plugin (version 1.15).
- Affected:
- up to 1.15.0.1
- Fixed in:
- 1.15.0.1
- Disclosed:
- Jan 6, 2020
Import and export users and customers 1.15 - Sensitive Data Exposure
high
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 via the export_users_csv function. This can allow authenticated attackers to export user information even if they do not have account creation privileges. The function was introduced in this version a...
- CVSS:
- 7.7
- Affected:
- 1.15 – 1.15
- Fixed in:
- 1.15.0.1
- Disclosed:
- Jan 1, 2020
Import and export users and customers [import-users-from-csv-with-meta] < 1.15.0.1
unknown
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 via the export_users_csv function. This can allow authenticated attackers to export user information even if they do not have account creation privileges. The function was introduced in this version a...
- Affected:
- up to 1.15.0.1
- Fixed in:
- 1.15.0.1
- Disclosed:
- Jan 1, 2020
Import and export users and customers [import-users-from-csv-with-meta] < 1.14.2.2
unknown
[en] The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
- Affected:
- up to 1.14.2.2
- Fixed in:
- 1.14.2.2
- Disclosed:
- Aug 22, 2019
CVE-2019-15326 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.14.0.3
unknown
[en] The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
- Affected:
- up to 1.14.0.3
- Fixed in:
- 1.14.0.3
- Disclosed:
- Aug 22, 2019
CVE-2019-15329 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.14.0.3
unknown
[en] The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
- Affected:
- up to 1.14.0.3
- Fixed in:
- 1.14.0.3
- Disclosed:
- Aug 22, 2019
CVE-2019-15328 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.14.1.3
unknown
[en] The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
- Affected:
- up to 1.14.1.3
- Fixed in:
- 1.14.1.3
- Disclosed:
- Aug 22, 2019
CVE-2019-15327 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.14.2.2
unknown
[en] The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
- Affected:
- up to 1.14.2.2
- Fixed in:
- 1.14.2.2
- Disclosed:
- Aug 8, 2019
CVE-2019-14683 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.14.2.2
unknown
Cross-Site Request Forgery (CSRF) vulnerability found in WordPress Import users from CSV with meta plugin (versions <= 1.14.1.3).
- Affected:
- up to 1.14.2.2
- Fixed in:
- 1.14.2.2
- Disclosed:
- Jun 26, 2019
Import and export users and customers <= 1.14.1.3 - Cross-Site Request Forgery leading to attachment deletion & Path Traversal
medium
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
- CVSS:
- 6.3
- Affected:
- up to 1.14.1.3
- Fixed in:
- 1.14.2.2
- Disclosed:
- Jun 22, 2019
CVE-2019-14683 on NVD →
Import and export users and customers <= 1.14.2.1 - Directory Traversal
high
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
- CVSS:
- 7.5
- Affected:
- up to 1.14.2.1
- Fixed in:
- 1.14.2.2
- Disclosed:
- Jun 20, 2019
CVE-2019-15326 on NVD →
Import and export users and customers <= 1.14.1.2 - Cross-Site Scripting
medium
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
- CVSS:
- 6.1
- Affected:
- up to 1.14.1.2
- Fixed in:
- 1.14.1.3
- Disclosed:
- Jun 20, 2019
CVE-2019-15327 on NVD →
Import and export users and customers <= 1.14.0.2 - Cross-Site Request Forgery
high
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.14.0.3
- Fixed in:
- 1.14.0.3
- Disclosed:
- Mar 14, 2019
CVE-2019-15329 on NVD →
Import and export users and customers <= 1.14.0.2 - Cross-Site Scripting
medium
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 1.14.0.3
- Fixed in:
- 1.14.0.3
- Disclosed:
- Mar 14, 2019
CVE-2019-15328 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.12.1
unknown
[en] The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.1
- Disclosed:
- Dec 12, 2018
CVE-2018-20101 on NVD →
Import users from CSV with meta <= 1.12 - Import Cross-Site Scripting
medium
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
- CVSS:
- 6.1
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.1
- Disclosed:
- Dec 11, 2018
CVE-2018-20101 on NVD →
Import and export users and customers [import-users-from-csv-with-meta] < 1.9.5
unknown
In the function acui_fileupload_process() there's no check for a nonce so a CSRF vulnerability exists.
Update the plugin.
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Sep 2, 2016
Import and export users and customers [import-users-from-csv-with-meta] < 1.9.5
unknown
In version 1.9.4.6, WordPress Import users from CSV with meta plugin, the function acui_delete_attachment() doesn't check for the current user capabilities so any logged in user can delete media files.
Update the plugin.
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Sep 2, 2016
Import and export users and customers [import-users-from-csv-with-meta] < 1.15.0.1
unknown
The export_users_csv function, registered as an authenticated AJAX call and allowing to export users, was missing the authorisation/capability check. CSRF check was in place, reducing the severity of the issue.
Only version 1.15 seems to be affected as the export functionality is a new feature introduced by it.
- Affected:
- up to 1.15.0.1
- Fixed in:
- 1.15.0.1