WordPress security by component
Import and export users and customers
Plugin description
Import and export users and customers is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 9.1.
Plugin slug:
import-and-export-users-and-customersLatest vulnerability
CVE-2026-16534: CSV imports permit administrator creation and account takeover
Import and export users and customers before 2.4.2 does not enforce WordPress role-assignment or per-user edit restrictions while importing CSV records. A user holding the user-creation capability can assign Administrator to a new account or overwrite an existing Administrator's email address or password, enabling privilege escalation and account takeover. The CNA record does not disclose the import route, CSV columns or import functions.
| Safe version |
|
||
|---|---|---|---|
| Aug 03, 2026 |
CVE-2026-16534
CSV imports permit administrator creation and account takeover
Import and export users and customers before 2.4.2 does not enforce WordPress role-assignment or per-user edit restrictions while importing CSV records. A user holding the user-creation capability can assign Administrator to a new account or overwrite an existing Administrator's email address or password, enabling privilege escalation and account takeover. The CNA record does not disclose the import route, CSV columns or import functions.
|
2.4.2 |
CVE9.1
NVDPending
|
| Aug 03, 2026 |
CVE-2025-15673
CSV import previews permit arbitrary server-file reads
Import and export users and customers before 2.4.3 does not restrict the filesystem path of a file read and displayed during CSV import. A high-privilege user with access to the import workflow can supply an arbitrary server path and disclose readable files. The CNA record does not disclose the route, path parameter, read function, output context or minimum capability.
|
2.4.3 |
CVE4.9
NVDPending
|
| May 15, 2024 |
CVE-2024-4734
Import and export users and customers: Cross-site scripting
Import and export users and customers is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.4
NVDPending
|
| May 15, 2024 |
CVE-2024-4656
Import and export users and customers: Cross-site scripting
Import and export users and customers is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Jan 11, 2024 |
CVE-2023-6624
Import and export users and customers: Cross-site scripting
Import and export users and customers is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.9
NVD5.4
|
| Jan 11, 2024 |
CVE-2023-6583
Import and export users and customers: Filesystem traversal
Import and export users and customers is affected by filesystem traversal. Exploitation requires an authenticated administrator account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.6
NVD7.2
|
| Nov 07, 2022 |
CVE-2022-3558
Import and export users and customers: A security weakness
Import and export users and customers is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.0
NVD8.0
|
| May 02, 2022 |
CVE-2022-1255
Import and export users and customers: Cross-site scripting
Import and export users and customers is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD4.8
|