Plugin Vulnerability Hub
Plugin 23 known issues Latest disclosed May 01, 2026

Import and export users and customers Vulnerabilities

Review known vulnerability records for the WordPress plugin Import and export users and customers (`import-users-from-csv-with-meta`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-7641, CVE-2026-3629 and CVE-2025-24689, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
23
High or Critical
8
Patch Coverage
100%
Last Updated
May 02, 2026
Related Security Guides

Use these guides while reviewing Import and export users and customers fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Import and export users and customers remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
19
1. Match the Package
Confirm the installed WordPress plugin slug is import-users-from-csv-with-meta before acting on any CVE from this cluster.
2. Sort by Severity
Start with 8 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
23 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Import and export users and customers CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
22
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2026-7641
Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privile...
Privilege Escalation Versions up to 2.0.8 2.0.9 CVSS 8.8
CVE-2019-15329
Import and export users and customers <= 1.14.0.2 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions before 1.14.0.3 1.14.0.3 CVSS 8.8
CVE-2026-3629
Import and export users and customers <= 1.29.7 - Privilege Escalation to Administra...
Privilege Escalation Versions up to 1.29.7 2.0 CVSS 8.1
CVE-2022-3558
Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV In...
Vulnerability Versions up to 1.20.4 1.20.5 CVSS 8.0
CVE-2019-15326
Import and export users and customers <= 1.14.2.1 - Directory Traversal
Vulnerability Versions up to 1.14.2.1 1.14.2.2 CVSS 7.5
CVE-2020-22277
Import and export users and customers <= 1.16.3.5 - CSV injection via a customer's p...
Vulnerability Versions up to 1.16.3.5 1.16.3.6 CVSS 7.3
CVE-2024-32817
Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object...
Vulnerability Versions up to 1.26.2 1.26.3 CVSS 7.2
CVE-2023-6583
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Dire...
Vulnerability Versions up to 1.24.2 1.24.3 CVSS 6.6
CVE-2026-7641 High 2.0.9
CVE-2026-7641 Import and export users and customers Privilege Escalation

Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields

CVE-2019-15329 High 1.14.0.3
CVE-2019-15329 Import and export users and customers Cross-Site Request Forgery

Import and export users and customers <= 1.14.0.2 - Cross-Site Request Forgery

CVE-2026-3629 High 2.0
CVE-2026-3629 Import and export users and customers Privilege Escalation

Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields

CVE-2022-3558 High 1.20.5
CVE-2022-3558 Import and export users and customers Vulnerability

Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV Injection

CVE-2019-15326 High 1.14.2.2
CVE-2019-15326 Import and export users and customers Vulnerability

Import and export users and customers <= 1.14.2.1 - Directory Traversal

CVE-2020-22277 High 1.16.3.6
CVE-2020-22277 Import and export users and customers Vulnerability

Import and export users and customers <= 1.16.3.5 - CSV injection via a customer's profile

CVE-2024-32817 High 1.26.3
CVE-2024-32817 Import and export users and customers Vulnerability

Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object Injection

CVE-2023-6583 Medium 1.24.3
CVE-2023-6583 Import and export users and customers Vulnerability

Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Import and export users and customers so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
23 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 8 high severity findings.
Recent CVEs
CVE-2026-7641, CVE-2026-3629 and CVE-2025-24689
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Import and export users and customers

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-7641
CVE-2026-7641: Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys...

Published
May 01, 2026
Patched Release
2.0.9
Affected Versions
Versions up to 2.0.8
Next Step
Update to 2.0.9 or newer if supported.
Plugin High Patched: Yes CVE-2026-3629
CVE-2026-3629: Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile...

Published
Mar 21, 2026
Patched Release
2.0
Affected Versions
Versions up to 1.29.7
Next Step
Update to 2.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-24689
CVE-2025-24689: Import and export users and customers <= 1.27.12 - Unauthenticated Sensitive Information Disclosure

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.27.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Published
Jan 27, 2025
Patched Release
1.27.13
Affected Versions
Versions up to 1.27.12
Next Step
Update to 1.27.13 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-50413
CVE-2024-50413: Import and export users and customers <= 1.27.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

Published
Oct 24, 2024
Patched Release
1.27.6
Affected Versions
Versions up to 1.27.5
Next Step
Update to 1.27.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-38787
CVE-2024-38787: Import and export users and customers <= 1.26.8 - Unauthenticated Information Exposure

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.26.8 via the fileupload_process function that uploads an import file in a public directory and does not subsequently delete it. T...

Published
Aug 07, 2024
Patched Release
1.26.9
Affected Versions
Versions up to 1.26.8
Next Step
Update to 1.26.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4734
CVE-2024-4734: Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

Published
May 14, 2024
Patched Release
1.26.7
Affected Versions
Versions up to 1.26.6.1
Next Step
Update to 1.26.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4656
CVE-2024-4656: Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...

Published
May 14, 2024
Patched Release
1.26.7
Affected Versions
Versions up to 1.26.6.1
Next Step
Update to 1.26.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-34815
CVE-2024-34815: Import and export users and customers <= 1.26.5 - Missing Authorization

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above...

Published
May 09, 2024
Patched Release
1.26.6
Affected Versions
Versions up to 1.26.5
Next Step
Update to 1.26.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-1050
CVE-2024-1050: Import and export users and customers <= 1.26.5 - Missing Authorization

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for au...

Published
May 03, 2024
Patched Release
1.26.6
Affected Versions
Versions up to 1.26.5
Next Step
Update to 1.26.6 or newer if supported.
Plugin High Patched: Yes CVE-2024-32817
CVE-2024-32817: Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object Injection

The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.26.2 via deserialization of untrusted input in the import.php file. This makes it possible for authenticated attackers, with administrator-...

Published
Apr 22, 2024
Patched Release
1.26.3
Affected Versions
Versions up to 1.26.2
Next Step
Update to 1.26.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-22151
CVE-2024-22151: Import and export users and customers <= 1.24.6 - Missing Authorization via fire_cron REST endpoint

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the fire_cron function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to trigge...

Published
Jan 16, 2024
Patched Release
1.24.7
Affected Versions
Versions up to 1.24.6
Next Step
Update to 1.24.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6624
CVE-2023-6624: Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This make...

Published
Dec 11, 2023
Patched Release
1.24.4
Affected Versions
Versions up to 1.24.3
Next Step
Update to 1.24.4 or newer if supported.