Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Import and export users and customers — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Import and export users and customers, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerabilities affecting the Import and export users and customers product, specifically categorized under weak credential reuse and data exposure weaknesses. It aggregates a comprehensive collection of security flaws, including improper access controls, insecure data handling, and privilege escalation issues, covering reported incidents from 2015 to the present. By consolidating these records, the page provides a centralized resource for analyzing the security posture of software tools used for migrating user data across platforms. Readers can discover the chronological evolution of a vendor’s advisories, allowing them to assess the responsiveness and consistency of security updates over time. Furthermore, users can understand the broader implications of a specific weakness class by observing its manifestation across different versions and configurations of the product. The aggregated data enables security teams to look up a product’s vulnerability history, identifying recurring patterns or systemic design flaws that may persist despite patching efforts. This historical context is essential for risk assessment, helping administrators determine if legacy versions remain vulnerable or if specific mitigation strategies have proven effective. The content supports informed decision-making for IT professionals responsible for maintaining data integrity during import and export operations. By examining these recorded weaknesses, stakeholders can better evaluate the potential risks associated with third-party data migration utilities and align their internal security policies accordingly.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-7641 Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields CWE-269 8.8 High2026-05-02
CVE-2026-3629 Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields CWE-269 8.1 High2026-03-21
CVE-2025-24689 WordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerability CWE-538 5.9 Medium2025-01-27
CVE-2024-50413 WordPress Import and export users and customers plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium2024-10-29
CVE-2024-38787 WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability CWE-201 7.5 High2024-08-13
CVE-2024-34815 WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability CWE-862 5.4 Medium2024-06-11
CVE-2024-22151 WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability CWE-862 5.3 Medium2024-06-08
CVE-2024-4656 Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium2024-05-15
CVE-2024-4734 Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium2024-05-15
CVE-2024-1050 Import and export users and customers <= 1.26.5 - Missing Authorization CWE-862 4.3 Medium2024-05-04
CVE-2024-32817 WordPress Import and export users and customers plugin <= 1.26.2 - PHP Object Injection vulnerability CWE-502 4.4 Medium2024-04-24
CVE-2023-6583 Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality CWE-98 6.6 Medium2024-01-11
CVE-2023-6624 Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode CWE-79 4.9 Medium2024-01-11
CVE-2022-3558 Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection CWE-1236 8.0 -2022-11-07
CVE-2022-1255 Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 -2022-05-02

All 15 known CVE vulnerabilities affecting Import and export users and customers with full Chinese analysis, references, and POCs where available.