Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.32%—Codection Import AND Export Users AND CustomersAI6/10/20266/10/2026
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
AplazadaAlta (7.5)0.30%—Codection Import AND Export Users AND CustomersAI30/9/202630/9/2026
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
AplazadaAlta (8.8)0.33%—Codection Import AND Export Users AND CustomersAI23/9/202624/9/2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape…
AplazadaAlta (7.2)0.46%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
AplazadaAlta (7.2)0.46%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
AplazadaMedia (4.1)0.18%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
AplazadaCrítica (9.1)0.40%—Codection Import AND Export Users AND CustomersAI3/8/202626/8/2026
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or…
AplazadaMedia (4.9)0.47%—Codection Import AND Export Users AND CustomersAI3/8/202629/9/2026
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
AplazadaMedia (4.3)0.39%—Codection Import AND Export Users AND CustomersAI10/7/202610/7/2026
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw…
AplazadaAlta (8)0.62%—Export User DataAI30/6/202630/6/2026
The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on…
AplazadaAlta (8.8)0.72%—Codection Import AND Export Users AND CustomersAI2/5/202617/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g.,…
AplazadaAlta (8.1)0.54%💥 PoCCodection Import AND Export Users AND CustomersAI21/3/202617/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields'…
AplazadaMedia (5.9)0.32%—Codection Import AND Export Users AND CustomersAI27/1/202517/6/2026
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Retrieve Embedded Sensitive Data.This issue affects Import and export users and customers: from n/a through <= 1.27.12.
AplazadaMedia (5.9)0.29%—Codection Import AND Export Users AND CustomersAI29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Stored XSS.This issue affects Import and export users and customers: from n/a through <= 1.27.5.
AplazadaAlta (7.5)0.42%—Codection Import AND Export Users AND CustomersAI13/8/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.8.
AplazadaMedia (5.4)0.37%—Codection Import AND Export Users AND CustomersAI11/6/202417/6/2026
Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5.
AnalizadaMedia (5.3)0.32%—Codection Import AND Export Users AND Customers8/6/202417/6/2026
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
AplazadaMedia (4.4)0.29%—Webtoffee Import AND Export Users AND CustomersAI15/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaMedia (4.4)0.26%—Codection Import AND Export Users AND CustomersAI15/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access…
AplazadaMedia (4.3)0.43%—Webtoffee Import AND Export Users AND CustomersAI4/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.4)0.37%—Codection Import AND Export Users AND CustomersAI24/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.2.
ModificadaMedia (5.4)0.35%—Codection Import AND Export Users AND Customers11/1/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaAlta (7.2)0.80%—Codection Import AND Export Users AND Customers11/1/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary…
ModificadaAlta (8.8)0.82%—Kaushikkalathiya Export Users Data7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1.
ModificadaAlta (8.8)0.80%—Narolainfotech Export Users Data Distinct7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.
Orbitaley — Vulnerabilidades