Import and export users and customers
import-users-from-csv-with-meta · eklenti
Import and export users and customers için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
23 bilinen açık
9 kayıt giriş yapmadan sömürülebilir · 1 kayıt için istismar kodu yayımlanmış · son kayıt 30 Eyl 2026
wordpress.org'da yayında · son sürüm 2.5.7 · son güncelleme 2 Eki 2026 · 70 bin+ kurulum
wordpress.org durumu 4 Eki 2026 tarihinde kontrol edildi
Güvenlik açıkları
- Yüksek 8.8
CVE-2019-15329kimlik doğrulamasız · tıklama gerekir
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
- Yüksek 8.8
CVE-2026-86583abone+≤ 2.4.17
Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip
- Yüksek 8.8
CVE-2026-7641abone+≤ 2.0.8
Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields
- Yüksek 8.1
CVE-2026-3629kimlik doğrulamasız≤ 1.29.7
Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields
- Yüksek 8.0
CVE-2022-3558abone+→ 1.20.5
Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection
- Yüksek 8.0
CVE-2020-22277giriş gerekir
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
- Yüksek 7.5
CVE-2024-38787kimlik doğrulamasız≤ 1.26.8
WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability
- Yüksek 7.5
CVE-2019-15326kimlik doğrulamasız
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
- Yüksek 7.5
CVE-2026-94178abone+≤ 2.5.2
WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability
- Orta 6.1
CVE-2019-15328kimlik doğrulamasız · tıklama gerekir
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
- Orta 6.1
CVE-2019-15327kimlik doğrulamasız · tıklama gerekir
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
- Orta 6.1
CVE-2018-20101kimlik doğrulamasız · tıklama gerekir
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
- Orta 5.9
CVE-2025-24689kimlik doğrulamasız≤ 1.27.12
WordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerability
- Orta 5.9
CVE-2024-50413yüksek yetki≤ 1.27.5
WordPress Import and export users and customers plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability
- Orta 5.7
CVE-2019-14683giriş gerekir
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attac
- Orta 5.4
CVE-2024-34815giriş gerekir≤ 1.26.5
WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability
- Orta 5.4
CVE-2023-6624katılımcı+≤ 1.24.3
Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
- Orta 5.3
CVE-2024-22151kimlik doğrulamasız≤ 1.24.6
WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability
- Orta 4.4
CVE-2024-4734yönetici≤ 1.26.6.1
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
- Orta 4.4
CVE-2024-4656yönetici≤ 1.26.6.1
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
- Orta 4.4
CVE-2024-32817yüksek yetki≤ 1.26.2
WordPress Import and export users and customers plugin <= 1.26.2 - PHP Object Injection vulnerability
- Orta 4.3
CVE-2026-15026abone+≤ 2.4.0
Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected
- Orta 4.3
CVE-2024-1050abone+≤ 1.26.5
Import and export users and customers <= 1.26.5 - Missing Authorization
Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).