Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Import and export users and customers — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Import and export users and customers, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the Import and export users and customers product category, focusing on common weakness types such as improper access control and data exposure. It compiles a comprehensive list of known issues reported across various vendor implementations and modules that facilitate the migration and synchronization of user and customer data between systems. The collection covers vulnerabilities disclosed from the early stages of these tools through the present day, ensuring a historical perspective on emerging threats in data import workflows. Here, security professionals can track individual vendor advisories to understand how specific developers have responded to critical flaws in their products. Users can also dive deeper into the characteristics of specific weakness classes to identify common patterns in how data ingestion mechanisms are exploited. Furthermore, the page allows for detailed lookups of a specific product’s vulnerability history, enabling teams to assess the long-term security posture of the software they rely on for daily operations. By centralizing this information, the resource supports proactive risk management and helps organizations prioritize patching efforts based on actual impact and prevalence. The data serves as a reference for auditing compliance and reviewing third-party dependencies within enterprise environments where large-scale user data transfers are routine.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2025-15673 Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read - - 2026-08-03
CVE-2026-16534 Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import - - 2026-08-03
CVE-2026-15026 Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action CWE-862 4.3 Medium 2026-07-10
CVE-2026-7641 Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields CWE-269 8.8 High 2026-05-02
CVE-2026-3629 Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields CWE-269 8.1 High 2026-03-21
CVE-2025-24689 WordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerability CWE-538 5.9 Medium 2025-01-27
CVE-2024-50413 WordPress Import and export users and customers plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-10-29
CVE-2024-38787 WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability CWE-201 7.5 High 2024-08-13
CVE-2024-34815 WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability CWE-862 5.4 Medium 2024-06-11
CVE-2024-22151 WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability CWE-862 5.3 Medium 2024-06-08
CVE-2024-4656 Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium 2024-05-15
CVE-2024-4734 Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium 2024-05-15
CVE-2024-1050 Import and export users and customers <= 1.26.5 - Missing Authorization CWE-862 4.3 Medium 2024-05-04
CVE-2024-32817 WordPress Import and export users and customers plugin <= 1.26.2 - PHP Object Injection vulnerability CWE-502 4.4 Medium 2024-04-24
CVE-2023-6583 Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality CWE-98 6.6 Medium 2024-01-11
CVE-2023-6624 Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode CWE-79 4.9 Medium 2024-01-11
CVE-2022-3558 Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection CWE-1236 8.0 - 2022-11-07
CVE-2022-1255 Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 - 2022-05-02

All 18 known CVE vulnerabilities affecting Import and export users and customers with full Chinese analysis, references, and POCs where available.