cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsimple-membership-wp-user-import simple-membership-wp-user-import

Direction: ascending
Jun 07, 2024

Simple Membership WP user Import # CVE-2023-0254

CVE, Research URL

CVE-2023-0254

Date
Jan 12, 2023
Research Description
The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 1.8.
Status
vulnerable
Feb 27, 2026

Simple Membership WP user Import # CVE-2026-24986

CVE, Research URL

CVE-2026-24986

Date
Feb 03, 2026
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership WP user Import: from n/a through <= 1.9.1.
Affected versions
max 1.9.1.
Status
vulnerable