Vulnerabilities and security researches forimport-users-from-csv-with-meta import-users-from-csv-with-meta
Direction: descendingApr 14, 2026
Import and export users and customers # CVE-2026-3629
- CVE, Research URL
- Application
- Date
- Mar 22, 2026
- Research Description
- The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' method does not include sensitive meta keys such as 'wp_capabilities'. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator by submitting a crafted registration request that sets the 'wp_capabilities' meta key. The vulnerability can only be exploited if the "Show fields in profile" setting is enabled and a CSV with a wp_capabilities column header has been previously imported.
- Affected versions
-
max 2.0.
- Status
-
vulnerable
Jan 28, 2025
Import and export users and customers # CVE-2025-24689
- CVE, Research URL
- Application
- Date
- Jan 27, 2025
- Research Description
- Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue affects Import and export users and customers: from n/a through 1.27.12.
- Affected versions
-
max 1.27.13.
- Status
-
vulnerable
Oct 28, 2024
Import and export users and customers # CVE-2024-50413
- CVE, Research URL
- Application
- Date
- Oct 29, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codection Import and export users and customers allows Stored XSS.This issue affects Import and export users and customers: from n/a through 1.27.5.
- Affected versions
-
max 1.27.6.
- Status
-
vulnerable
Aug 12, 2024
Import and export users and customers # CVE-2024-38787
- CVE, Research URL
- Application
- Date
- Aug 13, 2024
- Research Description
- Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
- Affected versions
-
max 1.26.9.
- Status
-
vulnerable
Jun 10, 2024
Import and export users and customers # CVE-2024-22151
- CVE, Research URL
- Application
- Date
- Jun 08, 2024
- Research Description
- Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
- Affected versions
-
max 1.24.7.
- Status
-
vulnerable
Jun 07, 2024
Import and export users and customers # CVE-2019-15327
- CVE, Research URL
- Application
- Date
- Aug 23, 2019
- Research Description
- The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
- Affected versions
-
max 1.14.1.3.
- Status
-
vulnerable
Import and export users and customers # CVE-2022-1255
- CVE, Research URL
- Application
- Date
- May 02, 2022
- Research Description
- The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues
- Affected versions
-
max 1.9.5.
- Status
-
vulnerable
Import and export users and customers # CVE-2020-22277
- CVE, Research URL
- Application
- Date
- Nov 04, 2020
- Research Description
- Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
- Affected versions
-
max 1.16.3.6.
- Status
-
vulnerable
Import and export users and customers # CVE-2019-14683
- CVE, Research URL
- Application
- Date
- Aug 09, 2019
- Research Description
- The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
- Affected versions
-
max 1.14.2.2.
- Status
-
vulnerable
Import and export users and customers # CVE-2019-15329
- CVE, Research URL
- Application
- Date
- Aug 23, 2019
- Research Description
- The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
- Affected versions
-
max 1.14.0.3.
- Status
-
vulnerable
Import and export users and customers # CVE-2022-3558
- CVE, Research URL
- Application
- Date
- Nov 07, 2022
- Research Description
- The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
- Affected versions
-
max 1.15.0.1.
- Status
-
vulnerable
Import and export users and customers # CVE-2019-15326
- CVE, Research URL
- Application
- Date
- Aug 23, 2019
- Research Description
- The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
- Affected versions
-
max 1.14.2.2.
- Status
-
vulnerable
Import and export users and customers # CVE-2019-15328
- CVE, Research URL
- Application
- Date
- Aug 23, 2019
- Research Description
- The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
- Affected versions
-
max 1.14.0.3.
- Status
-
vulnerable
Import and export users and customers # CVE-2018-20101
- CVE, Research URL
- Application
- Date
- Dec 12, 2018
- Research Description
- The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
- Affected versions
-
max 1.12.1.
- Status
-
vulnerable
Import and export users and customers # CVE-2023-6583
- CVE, Research URL
- Application
- Date
- Jan 11, 2024
- Research Description
- The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information.
- Affected versions
-
max 1.24.3.
- Status
-
vulnerable
Import and export users and customers # CVE-2023-6624
- CVE, Research URL
- Application
- Date
- Jan 11, 2024
- Research Description
- The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.24.4.
- Status
-
vulnerable
Import and export users and customers # CVE-2024-34815
- CVE, Research URL
- Application
- Date
- Jun 11, 2024
- Research Description
- Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.5.
- Affected versions
-
max 1.26.6.
- Status
-
vulnerable
Import and export users and customers # CVE-2024-4656
- CVE, Research URL
- Application
- Date
- May 15, 2024
- Research Description
- The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.26.7.
- Status
-
vulnerable
Import and export users and customers # CVE-2024-32817
- CVE, Research URL
- Application
- Date
- Apr 24, 2024
- Research Description
- Deserialization of Untrusted Data vulnerability in Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.2.
- Affected versions
-
max 1.26.3.
- Status
-
vulnerable
Import and export users and customers # CVE-2024-1050
- CVE, Research URL
- Application
- Date
- May 04, 2024
- Research Description
- The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all forced password resets.
- Affected versions
-
max 1.26.6.
- Status
-
vulnerable
Import and export users and customers # CVE-2024-4734
- CVE, Research URL
- Application
- Date
- May 15, 2024
- Research Description
- The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
- Affected versions
-
max 1.26.7.
- Status
-
vulnerable