Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2023-6583
Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information.
0
Attacker Value
Unknown
CVE-2022-3558
Disclosure Date: November 07, 2022 (last updated December 22, 2024)
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
0
Attacker Value
Unknown
CVE-2022-1255
Disclosure Date: May 02, 2022 (last updated February 23, 2025)
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2020-22277
Disclosure Date: November 04, 2020 (last updated February 22, 2025)
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
0