VendorsWebToffeeimport_export_wordpress_usersall versions
Vulnerabilities

WebToffee Import Export WordPress Users for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2020-12074
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
Published 2020-04-23 · Modified
8.8EPSS 0.017
CVE-2025-1970
Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
Published 2025-03-22 · Analyzed
7.6EPSS 0.004
CVE-2019-15092
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.
Published 2019-08-23 · Modified
7.31 PoCEPSS 0.051
CVE-2023-6558
Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Upload
Published 2024-01-11 · Modified
7.2EPSS 0.014
CVE-2023-3459
Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change
Published 2023-07-18 · Modified
7.2EPSS 0.009
CVE-2025-1971
Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
Published 2025-03-22 · Analyzed
7.2EPSS 0.008
CVE-2025-1972
Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
Published 2025-03-22 · Analyzed
6.5EPSS 0.004
CVE-2025-1973
Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
Published 2025-03-22 · Analyzed
4.9EPSS 0.007