CVE-2024-34815
Description
Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in WordPress Import and export users and customers plugin (<=1.26.5) allows unprivileged users to execute higher privileged actions.
The WordPress plugin "Import and export users and customers" by Javier Carazo is vulnerable to a broken access control issue in versions up to 1.26.5. The vulnerability stems from missing authorization checks, allowing unprivileged users to perform actions that should be restricted to higher-privileged roles [1][2].
An attacker can exploit this by sending crafted requests without proper authentication or nonce validation, potentially gaining the ability to import or export user data, including sensitive information. The attack does not require prior authentication and can be executed remotely, increasing the risk of mass exploitation [1].
The impact includes unauthorized access to user data, modification of user roles, or other administrative actions. This type of vulnerability is frequently used in mass-exploit campaigns targeting thousands of websites simultaneously [1].
Mitigation is available by updating the plugin to version 1.26.6 or later. Patchstack has also issued a mitigation rule to block attacks until the update is applied [2].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=1.26.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- patchstack.com/database/Wordpress/Plugin/import-users-from-csv-with-meta/vulnerability/wordpress-import-and-export-users-and-customers-plugin-1-26-5-broken-access-control-vulnerabilitynvd
- patchstack.com/database/vulnerability/import-users-from-csv-with-meta/wordpress-import-and-export-users-and-customers-plugin-1-26-5-broken-access-control-vulnerabilitynvd
News mentions
0No linked articles in our index yet.