VendorsCodectionimport_users_from_csv_with_metaall versions
Vulnerabilities

Codection Download Import Users from CSV with Meta

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2019-15329
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
Published 2019-08-22 · Modified
8.8EPSS 0.007
CVE-2019-15326
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
Published 2019-08-22 · Modified
7.5EPSS 0.023
CVE-2019-15328
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
Published 2019-08-22 · Modified
6.1EPSS 0.009
CVE-2019-15327
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
Published 2019-08-22 · Modified
6.1EPSS 0.009
CVE-2018-20101
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
Published 2018-12-12 · Modified
6.1EPSS 0.008
CVE-2019-14683
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
Published 2019-08-08 · Modified
5.7EPSS 0.007