Webtoffee
Webtoffee Import Export Wordpress Users: vulnerabilidades y CVE
Webtoffee Import Export Wordpress Users tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-1973 | Media (4.9) | 0.73% | — | 22 mar 2025 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated… |
| CVE-2025-1972 | Media (6.5) | 0.39% | — | 22 mar 2025 | The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including,… |
| CVE-2025-1971 | Alta (7.2) | 0.75% | — | 22 mar 2025 | The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter.… |
| CVE-2025-1970 | Alta (7.6) | 0.41% | — | 22 mar 2025 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for… |
| CVE-2024-32835 | Media (5.4) | 0.36% | — | 24 abr 2024 | Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3. |
| CVE-2024-30492 | Media (4.3) | 0.52% | — | 29 mar 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2. |
| CVE-2023-6558 | Alta (7.2) | 1.4% | — | 11 ene 2024 | The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including,… |
| CVE-2023-3459 | Alta (7.2) | 0.93% | — | 18 jul 2023 | The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in… |
| CVE-2020-12074 | Alta (8.8) | 1.7% | — | 23 abr 2020 | The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV. |
| CVE-2019-15092 | Alta (7.3) | 5.1% | — | 23 ago 2019 | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Webtoffee
Product Import Export FOR Woocommerce · 7Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels · 6Order Export & Order Import FOR Woocommerce · 5Wordpress Backup AND Migration · 3Product Feed FOR Woocommerce · 3Backup AND Migration · 3Stripe Payment Plugin FOR Woocommerce · 3Import AND Export Users AND Customers · 2Gdpr Cookie Consent · 2Order Export AND Order Import FOR Woocommerce · 2Smart Coupons FOR Woocommerce · 2Wordpress Comments Import AND Export · 2