Codection
Codection Import AND Export Users AND Customers: vulnerabilidades y CVE
Codection Import AND Export Users AND Customers tiene 22 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses10
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94178 | Alta (7.5) | 0.32% | — | 30 sept 2026 | Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions. |
| CVE-2026-86583 | Alta (8.8) | 0.33% | — | 23 sept 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability… |
| CVE-2026-92541 | Alta (7.2) | 0.46% | — | 20 sept 2026 | The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change… |
| CVE-2026-92540 | Alta (7.2) | 0.46% | — | 20 sept 2026 | The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users… |
| CVE-2026-16542 | Media (4.1) | 0.18% | — | 20 sept 2026 | The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side… |
| CVE-2026-16534 | Crítica (9.1) | 0.40% | — | 3 ago 2026 | The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation… |
| CVE-2025-15673 | Media (4.9) | 0.47% | — | 3 ago 2026 | The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the… |
| CVE-2026-15026 | Media (4.3) | 0.39% | — | 10 jul 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for… |
| CVE-2026-7641 | Alta (8.8) | 0.72% | — | 2 may 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an… |
| CVE-2026-3629 | Alta (8.1) | 0.54% | — | 21 mar 2026 | The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not… |
| CVE-2025-24689 | Media (5.9) | 0.32% | — | 27 ene 2025 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Retrieve Embedded Sensitive… |
| CVE-2024-50413 | Media (5.9) | 0.29% | — | 29 oct 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Stored XSS.This issue… |
| CVE-2024-38787 | Alta (7.5) | 0.42% | — | 13 ago 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a… |
| CVE-2024-34815 | Media (5.4) | 0.37% | — | 11 jun 2024 | Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5. |
| CVE-2024-22151 | Media (5.3) | 0.32% | — | 8 jun 2024 | Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6. |
| CVE-2024-4656 | Media (4.4) | 0.26% | — | 15 may 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization… |
| CVE-2024-32817 | Media (4.4) | 0.37% | — | 24 abr 2024 | Deserialization of Untrusted Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.2. |
| CVE-2023-6624 | Media (5.4) | 0.35% | — | 11 ene 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input… |
| CVE-2023-6583 | Alta (7.2) | 0.80% | — | 11 ene 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for… |
| CVE-2022-3558 | Alta (8) | 1.1% | — | 7 nov 2022 | The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files. |
| CVE-2022-1255 | Media (4.8) | 0.71% | — | 2 may 2022 | The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored… |
| CVE-2020-22277 | Alta (8) | 1.8% | — | 4 nov 2020 | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.