Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown

CVE-2025-24689

Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue affects Import and export users and customers: from n/a through 1.27.12.
0
Attacker Value
Unknown

CVE-2024-50413

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codection Import and export users and customers allows Stored XSS.This issue affects Import and export users and customers: from n/a through 1.27.5.
0
Attacker Value
Unknown

CVE-2024-8252

Disclosure Date: August 30, 2024 (last updated September 04, 2024)
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Attacker Value
Unknown

CVE-2024-38787

Disclosure Date: August 13, 2024 (last updated August 13, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
0
Attacker Value
Unknown

CVE-2024-34815

Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.5.
0
Attacker Value
Unknown

CVE-2024-22151

Disclosure Date: June 08, 2024 (last updated June 09, 2024)
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
0
Attacker Value
Unknown

CVE-2023-6624

Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-6583

Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information.
Attacker Value
Unknown

CVE-2022-4838

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-3558

Disclosure Date: November 07, 2022 (last updated December 22, 2024)
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.