Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
medium
The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the s...
- CVSS:
- 4.9
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Mar 21, 2025
CVE-2025-1973 on NVD →
Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
low
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to...
- CVSS:
- 2.7
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Mar 21, 2025
CVE-2025-1972 on NVD →
Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
high
The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject...
- CVSS:
- 7.2
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Mar 21, 2025
CVE-2025-1971 on NVD →
Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
high
The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locat...
- CVSS:
- 7.6
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Mar 21, 2025
CVE-2025-1970 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.5.4
unknown
[en] Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Apr 24, 2024
CVE-2024-32835 on NVD →
Export and Import Users and Customers <= 2.5.3 - Authenticated (Admin+) PHP Object Injection
high
The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.3 via deserialization of untrusted input in the import.php file. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP O...
- CVSS:
- 7.2
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Apr 22, 2024
CVE-2024-32835 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.5.3
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2.
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- Mar 29, 2024
CVE-2024-30492 on NVD →
Import Export WordPress Users <= 2.5.2 - Authenticated (Shop Manager+) Path Traversal
low
The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive inf...
- CVSS:
- 2.7
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Mar 28, 2024
CVE-2024-30492 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.4.9
unknown
[en] The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level capabilities or ab...
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Jan 11, 2024
CVE-2023-6558 on NVD →
Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Upload
high
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level capabilities or above,...
- CVSS:
- 7.2
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- Dec 12, 2023
CVE-2023-6558 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.4.2
unknown
[en] The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop m...
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Jul 18, 2023
CVE-2023-3459 on NVD →
Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change
high
The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop manage...
- CVSS:
- 7.2
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Jul 14, 2023
CVE-2023-3459 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 1.3.9
unknown
[en] The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- Apr 23, 2020
CVE-2020-12074 on NVD →
WebToffee Plugins <= (Various Versions) - Arbitrary User Creation
high
The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
- CVSS:
- 8.8
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- Mar 11, 2020
CVE-2020-12074 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 1.3.2
unknown
[en] The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Aug 23, 2019
CVE-2019-15092 on NVD →
Import Export WordPress Users and WooCommerce Customers <= 1.3.1 - CSV Injection
high
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.1 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.
- CVSS:
- 7.3
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Aug 22, 2018
CVE-2019-15092 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3
unknown
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
CVE-2025-1972 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3
unknown
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
CVE-2025-1973 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3
unknown
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
CVE-2025-1971 on NVD →
Export and Import Users and Customers [users-customers-import-export-for-wp-woocommerce] < 2.6.3
unknown
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
CVE-2025-1970 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database