plugin

Import Users From Csv With Meta Vulnerabilities

51 known security issues reported for the Import Users From Csv With Meta WordPress plugin. Most recent disclosed Jul 24, 2026.

8 high 17 medium

Running Import Users From Csv With Meta on your site? Check whether your installed version is affected.

Scan your site free

Import and export users and customers < 2.4.3 - Authenticated (Admin+) Arbitrary File Read

medium

The Import and export users and customers plugin for WordPress is vulnerable to Path Traversal in all versions up to 2.4.3 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive inform...

CVSS:
4.9
Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Jul 24, 2026

CVE-2025-15673 on NVD →

Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action

medium

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_c...

CVSS:
4.3
Affected:
up to 2.4.0
Fixed in:
2.4.1
Disclosed:
Jul 9, 2026

CVE-2026-15026 on NVD →

Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields

high

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g., `wp_capabil...

CVSS:
8.8
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
May 1, 2026

CVE-2026-7641 on NVD →

Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields

high

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' met...

CVSS:
8.1
Affected:
up to 1.29.7
Fixed in:
2.0
Disclosed:
Mar 21, 2026

CVE-2026-3629 on NVD →

Import and export users and customers <= 1.27.12 - Unauthenticated Sensitive Information Disclosure

medium

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.27.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.27.12
Fixed in:
1.27.13
Disclosed:
Jan 27, 2025

CVE-2025-24689 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.27.13

unknown

[en] Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue affects Import and export users and customers: from n/a through 1.27.12.

Affected:
up to 1.27.13
Fixed in:
1.27.13
Disclosed:
Jan 27, 2025

CVE-2025-24689 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.27.6

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codection Import and export users and customers allows Stored XSS.This issue affects Import and export users and customers: from n/a through 1.27.5.

Affected:
up to 1.27.6
Fixed in:
1.27.6
Disclosed:
Oct 29, 2024

CVE-2024-50413 on NVD →

Import and export users and customers <= 1.27.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitr...

CVSS:
4.4
Affected:
up to 1.27.5
Fixed in:
1.27.6
Disclosed:
Oct 24, 2024

CVE-2024-50413 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.26.9

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.

Affected:
up to 1.26.9
Fixed in:
1.26.9
Disclosed:
Aug 13, 2024

CVE-2024-38787 on NVD →

Import and export users and customers <= 1.26.8 - Unauthenticated Information Exposure

medium

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.26.8 via the fileupload_process function that uploads an import file in a public directory and does not subsequently delete it. This makes it possible for unauthenticate...

CVSS:
5.3
Affected:
up to 1.26.8
Fixed in:
1.26.9
Disclosed:
Aug 7, 2024

CVE-2024-38787 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.26.6

unknown

[en] Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.5.

Affected:
up to 1.26.6
Fixed in:
1.26.6
Disclosed:
Jun 11, 2024

CVE-2024-34815 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.24.7

unknown

[en] Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.

Affected:
up to 1.24.7
Fixed in:
1.24.7
Disclosed:
Jun 8, 2024

CVE-2024-22151 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.26.7

unknown

[en] The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator acc...

Affected:
up to 1.26.7
Fixed in:
1.26.7
Disclosed:
May 15, 2024

CVE-2024-4656 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.26.7

unknown

[en] The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm...

Affected:
up to 1.26.7
Fixed in:
1.26.7
Disclosed:
May 15, 2024

CVE-2024-4734 on NVD →

Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...

CVSS:
4.4
Affected:
up to 1.26.6.1
Fixed in:
1.26.7
Disclosed:
May 14, 2024

CVE-2024-4734 on NVD →

Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access a...

CVSS:
4.4
Affected:
up to 1.26.6.1
Fixed in:
1.26.7
Disclosed:
May 14, 2024

CVE-2024-4656 on NVD →

Import and export users and customers <= 1.26.5 - Missing Authorization

medium

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.26.5
Fixed in:
1.26.6
Disclosed:
May 9, 2024

CVE-2024-34815 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.26.6

unknown

[en] The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscri...

Affected:
up to 1.26.6
Fixed in:
1.26.6
Disclosed:
May 4, 2024

CVE-2024-1050 on NVD →

Import and export users and customers <= 1.26.5 - Missing Authorization

medium

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-l...

CVSS:
4.3
Affected:
up to 1.26.5
Fixed in:
1.26.6
Disclosed:
May 3, 2024

CVE-2024-1050 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.26.3

unknown

[en] Deserialization of Untrusted Data vulnerability in Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.2.

Affected:
up to 1.26.3
Fixed in:
1.26.3
Disclosed:
Apr 24, 2024

CVE-2024-32817 on NVD →

Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object Injection

high

The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.26.2 via deserialization of untrusted input in the import.php file. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP...

CVSS:
7.2
Affected:
up to 1.26.2
Fixed in:
1.26.3
Disclosed:
Apr 22, 2024

CVE-2024-32817 on NVD →

Import and export users and customers <= 1.24.6 - Missing Authorization via fire_cron REST endpoint

medium

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the fire_cron function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to trigger the plugin's cron job.

CVSS:
5.3
Affected:
up to 1.24.6
Fixed in:
1.24.7
Disclosed:
Jan 16, 2024

CVE-2024-22151 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.24.4

unknown

[en] The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

Affected:
up to 1.24.4
Fixed in:
1.24.4
Disclosed:
Jan 11, 2024

CVE-2023-6624 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.24.3

unknown

[en] The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitr...

Affected:
up to 1.24.3
Fixed in:
1.24.3
Disclosed:
Jan 11, 2024

CVE-2023-6583 on NVD →

Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...

CVSS:
4.9
Affected:
up to 1.24.3
Fixed in:
1.24.4
Disclosed:
Dec 11, 2023

CVE-2023-6624 on NVD →

Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality

medium

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary f...

CVSS:
6.6
Affected:
up to 1.24.2
Fixed in:
1.24.3
Disclosed:
Dec 8, 2023

CVE-2023-6583 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.20.5

unknown

[en] The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.

Affected:
up to 1.20.5
Fixed in:
1.20.5
Disclosed:
Nov 7, 2022

CVE-2022-3558 on NVD →

Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV Injection

high

The Import and export users and customers plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.20.4. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system...

CVSS:
8
Affected:
up to 1.20.4
Fixed in:
1.20.5
Disclosed:
Oct 17, 2022

CVE-2022-3558 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.19.2.1

unknown

[en] The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues

Affected:
up to 1.19.2.1
Fixed in:
1.19.2.1
Disclosed:
May 2, 2022

CVE-2022-1255 on NVD →

Import and export users and customers <= 1.19.2 - Stored Cross-Site Scripting

medium

The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitize and escape imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues

CVSS:
5.5
Affected:
up to 1.19.2.1
Fixed in:
1.19.2.1
Disclosed:
Apr 11, 2022

CVE-2022-1255 on NVD →

Import and export users and customers <= 1.16.3.5 - CSV injection via a customer's profile

high

Import and export users and customers WordPress Plugin through 1.16.3.5 allows CSV injection via a customer's profile.

CVSS:
7.3
Affected:
up to 1.16.3.5
Fixed in:
1.16.3.6
Disclosed:
Nov 20, 2020

CVE-2020-22277 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.16.3.6

unknown

[en] Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

Affected:
up to 1.16.3.6
Fixed in:
1.16.3.6
Disclosed:
Nov 4, 2020

CVE-2020-22277 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.15.0.1

unknown

Unauthorised Authenticated Users Export vulnerability found in WordPress Import Users From CSV with Meta plugin (version 1.15).

Affected:
up to 1.15.0.1
Fixed in:
1.15.0.1
Disclosed:
Jan 6, 2020

Import and export users and customers 1.15 - Sensitive Data Exposure

high

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 via the export_users_csv function. This can allow authenticated attackers to export user information even if they do not have account creation privileges. The function was introduced in this version a...

CVSS:
7.7
Affected:
1.15 – 1.15
Fixed in:
1.15.0.1
Disclosed:
Jan 1, 2020

Import and export users and customers [import-users-from-csv-with-meta] < 1.15.0.1

unknown

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 via the export_users_csv function. This can allow authenticated attackers to export user information even if they do not have account creation privileges. The function was introduced in this version a...

Affected:
up to 1.15.0.1
Fixed in:
1.15.0.1
Disclosed:
Jan 1, 2020

Import and export users and customers [import-users-from-csv-with-meta] < 1.14.2.2

unknown

[en] The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

Affected:
up to 1.14.2.2
Fixed in:
1.14.2.2
Disclosed:
Aug 22, 2019

CVE-2019-15326 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.14.0.3

unknown

[en] The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

Affected:
up to 1.14.0.3
Fixed in:
1.14.0.3
Disclosed:
Aug 22, 2019

CVE-2019-15329 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.14.0.3

unknown

[en] The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

Affected:
up to 1.14.0.3
Fixed in:
1.14.0.3
Disclosed:
Aug 22, 2019

CVE-2019-15328 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.14.1.3

unknown

[en] The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

Affected:
up to 1.14.1.3
Fixed in:
1.14.1.3
Disclosed:
Aug 22, 2019

CVE-2019-15327 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.14.2.2

unknown

[en] The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

Affected:
up to 1.14.2.2
Fixed in:
1.14.2.2
Disclosed:
Aug 8, 2019

CVE-2019-14683 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.14.2.2

unknown

Cross-Site Request Forgery (CSRF) vulnerability found in WordPress Import users from CSV with meta plugin (versions <= 1.14.1.3).

Affected:
up to 1.14.2.2
Fixed in:
1.14.2.2
Disclosed:
Jun 26, 2019

Import and export users and customers <= 1.14.1.3 - Cross-Site Request Forgery leading to attachment deletion & Path Traversal

medium

The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

CVSS:
6.3
Affected:
up to 1.14.1.3
Fixed in:
1.14.2.2
Disclosed:
Jun 22, 2019

CVE-2019-14683 on NVD →

Import and export users and customers <= 1.14.2.1 - Directory Traversal

high

The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

CVSS:
7.5
Affected:
up to 1.14.2.1
Fixed in:
1.14.2.2
Disclosed:
Jun 20, 2019

CVE-2019-15326 on NVD →

Import and export users and customers <= 1.14.1.2 - Cross-Site Scripting

medium

The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

CVSS:
6.1
Affected:
up to 1.14.1.2
Fixed in:
1.14.1.3
Disclosed:
Jun 20, 2019

CVE-2019-15327 on NVD →

Import and export users and customers <= 1.14.0.2 - Cross-Site Request Forgery

high

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

CVSS:
8.8
Affected:
up to 1.14.0.3
Fixed in:
1.14.0.3
Disclosed:
Mar 14, 2019

CVE-2019-15329 on NVD →

Import and export users and customers <= 1.14.0.2 - Cross-Site Scripting

medium

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 1.14.0.3
Fixed in:
1.14.0.3
Disclosed:
Mar 14, 2019

CVE-2019-15328 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.12.1

unknown

[en] The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

Affected:
up to 1.12.1
Fixed in:
1.12.1
Disclosed:
Dec 12, 2018

CVE-2018-20101 on NVD →

Import users from CSV with meta <= 1.12 - Import Cross-Site Scripting

medium

The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

CVSS:
6.1
Affected:
up to 1.12.1
Fixed in:
1.12.1
Disclosed:
Dec 11, 2018

CVE-2018-20101 on NVD →

Import and export users and customers [import-users-from-csv-with-meta] < 1.9.5

unknown

In the function acui_fileupload_process() there's no check for a nonce so a CSRF vulnerability exists. Update the plugin.

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Sep 2, 2016

Import and export users and customers [import-users-from-csv-with-meta] < 1.9.5

unknown

In version 1.9.4.6, WordPress Import users from CSV with meta plugin, the function acui_delete_attachment() doesn't check for the current user capabilities so any logged in user can delete media files. Update the plugin.

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Sep 2, 2016

Import and export users and customers [import-users-from-csv-with-meta] < 1.15.0.1

unknown

The export_users_csv function, registered as an authenticated AJAX call and allowing to export users, was missing the authorisation/capability check. CSRF check was in place, reducing the severity of the issue. Only version 1.15 seems to be affected as the export functionality is a new feature introduced by it.

Affected:
up to 1.15.0.1
Fixed in:
1.15.0.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database