cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forimport-users-from-csv-with-meta import-users-from-csv-with-meta

Direction: ascending
Jun 07, 2024

Import and export users and customers # CVE-2019-15327

CVE, Research URL

CVE-2019-15327

Date
Aug 23, 2019
Research Description
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
Affected versions
max 1.14.1.3.
Status
vulnerable

Import and export users and customers # CVE-2022-1255

CVE, Research URL

CVE-2022-1255

Date
May 02, 2022
Research Description
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues
Affected versions
max 1.9.5.
Status
vulnerable

Import and export users and customers # CVE-2020-22277

CVE, Research URL

CVE-2020-22277

Date
Nov 04, 2020
Research Description
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
Affected versions
max 1.16.3.6.
Status
vulnerable

Import and export users and customers # CVE-2019-14683

CVE, Research URL

CVE-2019-14683

Date
Aug 09, 2019
Research Description
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
Affected versions
max 1.14.2.2.
Status
vulnerable

Import and export users and customers # CVE-2019-15329

CVE, Research URL

CVE-2019-15329

Date
Aug 23, 2019
Research Description
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
Affected versions
max 1.14.0.3.
Status
vulnerable

Import and export users and customers # CVE-2022-3558

CVE, Research URL

CVE-2022-3558

Date
Nov 07, 2022
Research Description
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
Affected versions
max 1.15.0.1.
Status
vulnerable

Import and export users and customers # CVE-2019-15326

CVE, Research URL

CVE-2019-15326

Date
Aug 23, 2019
Research Description
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
Affected versions
max 1.14.2.2.
Status
vulnerable

Import and export users and customers # CVE-2019-15328

CVE, Research URL

CVE-2019-15328

Date
Aug 23, 2019
Research Description
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
Affected versions
max 1.14.0.3.
Status
vulnerable

Import and export users and customers # CVE-2018-20101

CVE, Research URL

CVE-2018-20101

Date
Dec 12, 2018
Research Description
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
Affected versions
max 1.12.1.
Status
vulnerable

Import and export users and customers # CVE-2023-6583

CVE, Research URL

CVE-2023-6583

Date
Jan 11, 2024
Research Description
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information.
Affected versions
max 1.24.3.
Status
vulnerable

Import and export users and customers # CVE-2023-6624

CVE, Research URL

CVE-2023-6624

Date
Jan 11, 2024
Research Description
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.24.4.
Status
vulnerable

Import and export users and customers # CVE-2024-34815

CVE, Research URL

CVE-2024-34815

Date
Jun 11, 2024
Research Description
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.5.
Affected versions
max 1.26.6.
Status
vulnerable

Import and export users and customers # CVE-2024-4656

CVE, Research URL

CVE-2024-4656

Date
May 15, 2024
Research Description
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.26.7.
Status
vulnerable

Import and export users and customers # CVE-2024-32817

CVE, Research URL

CVE-2024-32817

Date
Apr 24, 2024
Research Description
Deserialization of Untrusted Data vulnerability in Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.2.
Affected versions
max 1.26.3.
Status
vulnerable

Import and export users and customers # CVE-2024-1050

CVE, Research URL

CVE-2024-1050

Date
May 04, 2024
Research Description
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all forced password resets.
Affected versions
max 1.26.6.
Status
vulnerable

Import and export users and customers # CVE-2024-4734

CVE, Research URL

CVE-2024-4734

Date
May 15, 2024
Research Description
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 1.26.7.
Status
vulnerable
Jun 10, 2024

Import and export users and customers # CVE-2024-22151

CVE, Research URL

CVE-2024-22151

Date
Jun 08, 2024
Research Description
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
Affected versions
max 1.24.7.
Status
vulnerable
Aug 12, 2024

Import and export users and customers # CVE-2024-38787

CVE, Research URL

CVE-2024-38787

Date
Aug 13, 2024
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
Affected versions
max 1.26.9.
Status
vulnerable
Oct 28, 2024

Import and export users and customers # CVE-2024-50413

CVE, Research URL

CVE-2024-50413

Date
Oct 29, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codection Import and export users and customers allows Stored XSS.This issue affects Import and export users and customers: from n/a through 1.27.5.
Affected versions
max 1.27.6.
Status
vulnerable
Jan 28, 2025

Import and export users and customers # CVE-2025-24689

CVE, Research URL

CVE-2025-24689

Date
Jan 27, 2025
Research Description
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue affects Import and export users and customers: from n/a through 1.27.12.
Affected versions
max 1.27.13.
Status
vulnerable
Apr 14, 2026

Import and export users and customers # CVE-2026-3629

CVE, Research URL

CVE-2026-3629

Date
Mar 22, 2026
Research Description
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' method does not include sensitive meta keys such as 'wp_capabilities'. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator by submitting a crafted registration request that sets the 'wp_capabilities' meta key. The vulnerability can only be exploited if the "Show fields in profile" setting is enabled and a CSV with a wp_capabilities column header has been previously imported.
Affected versions
max 2.0.
Status
vulnerable