Skip to content
Noroxi

Import and export users and customers

import-users-from-csv-with-meta · plugin

Known security vulnerabilities for Import and export users and customers. Find out in seconds which version runs on your site with WP Lens.

23 known vulnerabilities

9 exploitable without logging in · 1 with public exploit code · latest Sep 30, 2026

Listed on wordpress.org · latest 2.5.7 · last updated Oct 2, 2026 · 70K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2019-15329unauthenticated · needs a click

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

    High 8.8
  • CVE-2026-86583subscriber+≤ 2.4.17

    Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip

    High 8.8
  • CVE-2026-7641subscriber+≤ 2.0.8

    Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields

    High 8.8
  • CVE-2026-3629unauthenticated≤ 1.29.7

    Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields

    High 8.1
  • CVE-2022-3558subscriber+→ 1.20.5

    Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection

    High 8.0
  • CVE-2020-22277login required

    Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

    High 8.0
  • CVE-2024-38787unauthenticated≤ 1.26.8

    WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability

    High 7.5
  • CVE-2019-15326unauthenticated

    The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

    High 7.5
  • CVE-2026-94178subscriber+≤ 2.5.2

    WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability

    High 7.5
  • CVE-2019-15328unauthenticated · needs a click

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

    Medium 6.1
  • CVE-2019-15327unauthenticated · needs a click

    The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

    Medium 6.1
  • CVE-2018-20101unauthenticated · needs a click

    The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

    Medium 6.1
  • CVE-2025-24689unauthenticated≤ 1.27.12

    WordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerability

    Medium 5.9
  • CVE-2024-50413high privilege≤ 1.27.5

    WordPress Import and export users and customers plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability

    Medium 5.9
  • CVE-2019-14683login required

    The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attac

    Medium 5.7
  • CVE-2024-34815login required≤ 1.26.5

    WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability

    Medium 5.4
  • CVE-2023-6624contributor+≤ 1.24.3

    Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

    Medium 5.4
  • CVE-2024-22151unauthenticated≤ 1.24.6

    WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2024-4734admin≤ 1.26.6.1

    Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Medium 4.4
  • CVE-2024-4656admin≤ 1.26.6.1

    Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Medium 4.4
  • CVE-2024-32817high privilege≤ 1.26.2

    WordPress Import and export users and customers plugin <= 1.26.2 - PHP Object Injection vulnerability

    Medium 4.4
  • CVE-2026-15026subscriber+≤ 2.4.0

    Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected

    Medium 4.3
  • CVE-2024-1050subscriber+≤ 1.26.5

    Import and export users and customers <= 1.26.5 - Missing Authorization

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory