plugin

Users Customers Import Export For Wp Woocommerce Vulnerabilities

20 known security issues reported for the Users Customers Import Export For Wp Woocommerce WordPress plugin. Most recent disclosed Mar 21, 2025.

7 high 1 medium 2 low

Running Users Customers Import Export For Wp Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function

medium

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the s...

CVSS:
4.9
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Mar 21, 2025

CVE-2025-1973 on NVD →

Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function

low

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to...

CVSS:
2.7
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Mar 21, 2025

CVE-2025-1972 on NVD →

Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

high

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject...

CVSS:
7.2
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Mar 21, 2025

CVE-2025-1971 on NVD →

Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

high

The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locat...

CVSS:
7.6
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Mar 21, 2025

CVE-2025-1970 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.5.4

unknown

[en] Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3.

Affected:
up to 2.5.4
Fixed in:
2.5.4
Disclosed:
Apr 24, 2024

CVE-2024-32835 on NVD →

Export and Import Users and Customers <= 2.5.3 - Authenticated (Admin+) PHP Object Injection

high

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.3 via deserialization of untrusted input in the import.php file. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP O...

CVSS:
7.2
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Apr 22, 2024

CVE-2024-32835 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.5.3

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2.

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Mar 29, 2024

CVE-2024-30492 on NVD →

Import Export WordPress Users <= 2.5.2 - Authenticated (Shop Manager+) Path Traversal

low

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive inf...

CVSS:
2.7
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Mar 28, 2024

CVE-2024-30492 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.4.9

unknown

[en] The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level capabilities or ab...

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Jan 11, 2024

CVE-2023-6558 on NVD →

Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Upload

high

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level capabilities or above,...

CVSS:
7.2
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Dec 12, 2023

CVE-2023-6558 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.4.2

unknown

[en] The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop m...

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Jul 18, 2023

CVE-2023-3459 on NVD →

Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change

high

The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop manage...

CVSS:
7.2
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Jul 14, 2023

CVE-2023-3459 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 1.3.9

unknown

[en] The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.

Affected:
up to 1.3.9
Fixed in:
1.3.9
Disclosed:
Apr 23, 2020

CVE-2020-12074 on NVD →

WebToffee Plugins <= (Various Versions) - Arbitrary User Creation

high

The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.

CVSS:
8.8
Affected:
up to 1.3.9
Fixed in:
1.3.9
Disclosed:
Mar 11, 2020

CVE-2020-12074 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 1.3.2

unknown

[en] The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Aug 23, 2019

CVE-2019-15092 on NVD →

Import Export WordPress Users and WooCommerce Customers <= 1.3.1 - CSV Injection

high

The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.1 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.

CVSS:
7.3
Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Aug 22, 2018

CVE-2019-15092 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3

unknown
Affected:
up to 2.6.3
Fixed in:
2.6.3

CVE-2025-1972 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3

unknown
Affected:
up to 2.6.3
Fixed in:
2.6.3

CVE-2025-1973 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3

unknown
Affected:
up to 2.6.3
Fixed in:
2.6.3

CVE-2025-1971 on NVD →

Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3

unknown
Affected:
up to 2.6.3
Fixed in:
2.6.3

CVE-2025-1970 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database