WordPress Users & WooCommerce Customers Import Export
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-22277 | Hig | 0.52 | 8.0 | 0.02 | Nov 4, 2020 | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. | ||
| CVE-2019-15092 | Hig | 0.51 | 7.3 | 0.05 | Aug 23, 2019 | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class. | ||
| CVE-2022-1255 | Med | 0.31 | 4.8 | 0.01 | May 2, 2022 | The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues |
- risk 0.52cvss 8.0epss 0.02
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
- risk 0.51cvss 7.3epss 0.05
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.
- risk 0.31cvss 4.8epss 0.01
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues