« Volver al listado

Codection

Codection Import AND Export Users AND Customers: vulnerabilidades y CVE

Codection Import AND Export Users AND Customers tiene 22 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE22
Últimos 12 meses10
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-94178Alta (7.5)0.32%—30 sept 2026
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
CVE-2026-86583Alta (8.8)0.33%—23 sept 2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability…
CVE-2026-92541Alta (7.2)0.46%—20 sept 2026
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change…
CVE-2026-92540Alta (7.2)0.46%—20 sept 2026
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users…
CVE-2026-16542Media (4.1)0.18%—20 sept 2026
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side…
CVE-2026-16534Crítica (9.1)0.40%—3 ago 2026
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation…
CVE-2025-15673Media (4.9)0.47%—3 ago 2026
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the…
CVE-2026-15026Media (4.3)0.39%—10 jul 2026
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for…
CVE-2026-7641Alta (8.8)0.72%—2 may 2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an…
CVE-2026-3629Alta (8.1)0.54%—21 mar 2026
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not…
CVE-2025-24689Media (5.9)0.32%—27 ene 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Retrieve Embedded Sensitive…
CVE-2024-50413Media (5.9)0.29%—29 oct 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Stored XSS.This issue…
CVE-2024-38787Alta (7.5)0.42%—13 ago 2024
Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a…
CVE-2024-34815Media (5.4)0.37%—11 jun 2024
Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5.
CVE-2024-22151Media (5.3)0.32%—8 jun 2024
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
CVE-2024-4656Media (4.4)0.26%—15 may 2024
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization…
CVE-2024-32817Media (4.4)0.37%—24 abr 2024
Deserialization of Untrusted Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.2.
CVE-2023-6624Media (5.4)0.35%—11 ene 2024
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input…
CVE-2023-6583Alta (7.2)0.80%—11 ene 2024
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for…
CVE-2022-3558Alta (8)1.1%—7 nov 2022
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
CVE-2022-1255Media (4.8)0.71%—2 may 2022
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored…
CVE-2020-22277Alta (8)1.8%—4 nov 2020
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services6
  2. T1068 Exploitation for Privilege Escalation2
  3. T1098.002 Additional Email Delegate Permissions2
  4. T1190 Exploit Public-Facing Application2
  5. T1078.001 Default Accounts1
  6. T1090 Proxy1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Codection