İçeriğe atla
Noroxi

Import and export users and customers

import-users-from-csv-with-meta · eklenti

Import and export users and customers için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

23 bilinen açık

9 kayıt giriş yapmadan sömürülebilir · 1 kayıt için istismar kodu yayımlanmış · son kayıt 30 Eyl 2026

wordpress.org'da yayında · son sürüm 2.5.7 · son güncelleme 2 Eki 2026 · 70 bin+ kurulum

wordpress.org durumu 4 Eki 2026 tarihinde kontrol edildi

Güvenlik açıkları

  • CVE-2019-15329kimlik doğrulamasız · tıklama gerekir

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

    Yüksek 8.8
  • CVE-2026-86583abone+≤ 2.4.17

    Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip

    Yüksek 8.8
  • CVE-2026-7641abone+≤ 2.0.8

    Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields

    Yüksek 8.8
  • CVE-2026-3629kimlik doğrulamasız≤ 1.29.7

    Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields

    Yüksek 8.1
  • CVE-2022-3558abone+→ 1.20.5

    Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection

    Yüksek 8.0
  • CVE-2020-22277giriş gerekir

    Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

    Yüksek 8.0
  • CVE-2024-38787kimlik doğrulamasız≤ 1.26.8

    WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability

    Yüksek 7.5
  • CVE-2019-15326kimlik doğrulamasız

    The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

    Yüksek 7.5
  • CVE-2026-94178abone+≤ 2.5.2

    WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability

    Yüksek 7.5
  • CVE-2019-15328kimlik doğrulamasız · tıklama gerekir

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

    Orta 6.1
  • CVE-2019-15327kimlik doğrulamasız · tıklama gerekir

    The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

    Orta 6.1
  • CVE-2018-20101kimlik doğrulamasız · tıklama gerekir

    The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

    Orta 6.1
  • CVE-2025-24689kimlik doğrulamasız≤ 1.27.12

    WordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerability

    Orta 5.9
  • CVE-2024-50413yüksek yetki≤ 1.27.5

    WordPress Import and export users and customers plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability

    Orta 5.9
  • CVE-2019-14683giriş gerekir

    The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attac

    Orta 5.7
  • CVE-2024-34815giriş gerekir≤ 1.26.5

    WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability

    Orta 5.4
  • CVE-2023-6624katılımcı+≤ 1.24.3

    Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

    Orta 5.4
  • CVE-2024-22151kimlik doğrulamasız≤ 1.24.6

    WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability

    Orta 5.3
  • CVE-2024-4734yönetici≤ 1.26.6.1

    Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Orta 4.4
  • CVE-2024-4656yönetici≤ 1.26.6.1

    Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Orta 4.4
  • CVE-2024-32817yüksek yetki≤ 1.26.2

    WordPress Import and export users and customers plugin <= 1.26.2 - PHP Object Injection vulnerability

    Orta 4.4
  • CVE-2026-15026abone+≤ 2.4.0

    Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected

    Orta 4.3
  • CVE-2024-1050abone+≤ 1.26.5

    Import and export users and customers <= 1.26.5 - Missing Authorization

    Orta 4.3

Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).

← Dizine dön