WordPress Import and export users and customers是WordPress基金会的一个支持用户与客户数据导入导出的工具。 WordPress Import and export users and customers 2.4.2之前版本存在安全漏洞,该漏洞源于CSV导入期间未强制执行WordPress的角色分配和每用户编辑权限,可能导致拥有用户创建权限的用户创建管理员账户并覆盖现有管理员的密码或电子邮件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Import and export users and customers | < 2.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Import and export users and customers | 0 ~ 2.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16060 | Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File | |
| CVE-2026-16057 | Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from | |
| CVE-2026-16274 | Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_blo | |
| CVE-2026-15254 | Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admi | |
| CVE-2025-15672 | Chama < 1.0.13 - Unauthenticated PHP Object Injection | |
| CVE-2025-15673 | Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read | |
| CVE-2026-16532 | Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission For | |
| CVE-2026-16276 | Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_ | |
| CVE-2026-13340 | SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass | |
| CVE-2026-12872 | Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-12965 | Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking | |
| CVE-2026-14557 | SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass | |
| CVE-2026-15231 | TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR | |
| CVE-2026-16565 | Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute | |
| CVE-2026-16250 | Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-15383 | Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header | |
| CVE-2026-15260 | Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion v | |
| CVE-2026-15931 | Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber | |
| CVE-2026-15930 | Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registratio | |
| CVE-2026-16539 | SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet