Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Import and export users and customers — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Import and export users and customers, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the "Import and export users and customers" product, categorized by vendor, product, weakness type, and associated tags. It collects a comprehensive set of security flaws affecting this specific product, covering the full historical timeline of recorded advisories and patches. Users can utilize this aggregation to track a vendor's advisory history, understand the distribution of a specific weakness class, or look up the complete vulnerability history of the product. The data is presented to facilitate analysis of recurring issues and remediation patterns.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-94178 WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability CWE-266 7.5 High 2026-09-30
CVE-2026-86583 Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields CWE-266 8.8 High 2026-09-23
CVE-2026-92541 Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer - - 2026-09-20
CVE-2026-92540 Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_users - - 2026-09-20
CVE-2026-16542 Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar - - 2026-09-20
CVE-2025-15673 Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read - - 2026-08-03
CVE-2026-16534 Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import - - 2026-08-03
CVE-2026-15026 Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action CWE-862 4.3 Medium 2026-07-10
CVE-2026-7641 Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields CWE-269 8.8 High 2026-05-02
CVE-2026-3629 Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields CWE-269 8.1 High 2026-03-21
CVE-2025-24689 WordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerability CWE-538 5.9 Medium 2025-01-27
CVE-2024-50413 WordPress Import and export users and customers plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-10-29
CVE-2024-38787 WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability CWE-201 7.5 High 2024-08-13
CVE-2024-34815 WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability CWE-862 5.4 Medium 2024-06-11
CVE-2024-22151 WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability CWE-862 5.3 Medium 2024-06-08
CVE-2024-4656 Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium 2024-05-15
CVE-2024-4734 Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium 2024-05-15
CVE-2024-1050 Import and export users and customers <= 1.26.5 - Missing Authorization CWE-862 4.3 Medium 2024-05-04
CVE-2024-32817 WordPress Import and export users and customers plugin <= 1.26.2 - PHP Object Injection vulnerability CWE-502 4.4 Medium 2024-04-24
CVE-2023-6583 Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality CWE-98 6.6 Medium 2024-01-11
CVE-2023-6624 Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode CWE-79 4.9 Medium 2024-01-11
CVE-2022-3558 Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection CWE-1236 8.0 - 2022-11-07
CVE-2022-1255 Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 - 2022-05-02

All 23 known CVE vulnerabilities affecting Import and export users and customers with full Chinese analysis, references, and POCs where available.