Перейти к содержимому
Noroxi

Import and export users and customers

import-users-from-csv-with-meta · плагин

Известные уязвимости для Import and export users and customers. Узнайте за секунды, какая версия работает на вашем сайте, с WP Lens.

23 известных уязвимостей

без входа эксплуатируется: 9 · 1 с публичным эксплойтом · последняя 30 сент. 2026 г.

Опубликован на wordpress.org · последняя версия 2.5.7 · обновлён 2 окт. 2026 г. · 70 тыс.+ установок

статус на wordpress.org проверен 2 окт. 2026 г.

Уязвимости

  • CVE-2019-15329без авторизации · нужен клик

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

    Высокий 8.8
  • CVE-2026-86583подписчик+≤ 2.4.17

    Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip

    Высокий 8.8
  • CVE-2026-7641подписчик+≤ 2.0.8

    Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields

    Высокий 8.8
  • CVE-2026-3629без авторизации≤ 1.29.7

    Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields

    Высокий 8.1
  • CVE-2022-3558подписчик+→ 1.20.5

    Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection

    Высокий 8.0
  • CVE-2020-22277нужен вход

    Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

    Высокий 8.0
  • CVE-2024-38787без авторизации≤ 1.26.8

    WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability

    Высокий 7.5
  • CVE-2019-15326без авторизации

    The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

    Высокий 7.5
  • CVE-2026-94178подписчик+≤ 2.5.2

    WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability

    Высокий 7.5
  • CVE-2019-15328без авторизации · нужен клик

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

    Средний 6.1
  • CVE-2019-15327без авторизации · нужен клик

    The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

    Средний 6.1
  • CVE-2018-20101без авторизации · нужен клик

    The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

    Средний 6.1
  • CVE-2025-24689без авторизации≤ 1.27.12

    WordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerability

    Средний 5.9
  • CVE-2024-50413высокие права≤ 1.27.5

    WordPress Import and export users and customers plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability

    Средний 5.9
  • CVE-2019-14683нужен вход

    The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attac

    Средний 5.7
  • CVE-2024-34815нужен вход≤ 1.26.5

    WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability

    Средний 5.4
  • CVE-2023-6624участник+≤ 1.24.3

    Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

    Средний 5.4
  • CVE-2024-22151без авторизации≤ 1.24.6

    WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability

    Средний 5.3
  • CVE-2024-4734админ≤ 1.26.6.1

    Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Средний 4.4
  • CVE-2024-4656админ≤ 1.26.6.1

    Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Средний 4.4
  • CVE-2024-32817высокие права≤ 1.26.2

    WordPress Import and export users and customers plugin <= 1.26.2 - PHP Object Injection vulnerability

    Средний 4.4
  • CVE-2026-15026подписчик+≤ 2.4.0

    Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected

    Средний 4.3
  • CVE-2024-1050подписчик+≤ 1.26.5

    Import and export users and customers <= 1.26.5 - Missing Authorization

    Средний 4.3

Метка доступа берётся из текста самой записи (напр. «подписчик+»: подписчик и выше). Если роль не названа, по CVSS указывается «нужен вход» или «высокие права»; роль не выдумывается. «Нужен клик»: атака зависит от того, что авторизованный пользователь перейдёт по ссылке (CSRF, отражённый XSS).

← К каталогу