VYPR
Vendor

Codection

Products
3
CVEs
16
Across products
16
Status
Private

Products

3

Recent CVEs

16
  • CVE-2024-8252HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.03

    The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and…

  • CVE-2019-15329HigAug 22, 2019
    risk 0.57cvss 8.8epss 0.01

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

  • CVE-2022-3558HigNov 7, 2022
    risk 0.52cvss 8.0epss 0.01

    The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.

  • CVE-2020-22277HigNov 4, 2020
    risk 0.52cvss 8.0epss 0.02

    Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

  • CVE-2019-15326HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.02

    The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

  • CVE-2023-6583MedJan 11, 2024
    risk 0.43cvss 6.6epss 0.01

    The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to…

  • CVE-2017-8875MedMay 10, 2017
    risk 0.42cvss 6.5epss 0.01

    CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.

  • CVE-2019-15328MedAug 22, 2019
    risk 0.40cvss 6.1epss 0.01

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

  • CVE-2019-15327MedAug 22, 2019
    risk 0.40cvss 6.1epss 0.01

    The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

  • CVE-2015-9336MedAug 22, 2019
    risk 0.40cvss 6.1epss 0.01

    The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

  • CVE-2018-20101MedDec 12, 2018
    risk 0.40cvss 6.1epss 0.01

    The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

  • CVE-2019-14683MedAug 8, 2019
    risk 0.37cvss 5.7epss 0.01

    The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

  • CVE-2022-4838MedFeb 6, 2023
    risk 0.35cvss 5.4epss 0.01

    The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used…

  • CVE-2024-22151MedJun 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.

  • CVE-2023-6624MedJan 11, 2024
    risk 0.32cvss 4.9epss 0.00

    The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This…

  • CVE-2022-1255MedMay 2, 2022
    risk 0.31cvss 4.8epss 0.01

    The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues