What this page helps you verify fast
This hub clusters tracked records for Import and export users and customers so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Import and export users and customers (`import-users-from-csv-with-meta`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2026-7641, CVE-2026-3629 and CVE-2025-24689, so operators can jump from disclosure to patch validation without scanning the full feed first.
Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.
Review patch cadence, privileged access, XML-RPC exposure, backups, and monitoring controls.
Use ownership, update testing, least privilege, and removal criteria to reduce plugin risk.
Compare scanner coverage for plugin CVEs, version detection, alert noise, and remediation workflow.
Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.
Affected range: Versions up to 2.0.8. Fixed version: 2.0.9.
Affected range: Versions before 1.14.0.3. Fixed version: 1.14.0.3.
Affected range: Versions up to 1.29.7. Fixed version: 2.0.
Affected range: Versions up to 1.20.4. Fixed version: 1.20.5.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
| Tracked CVE | Issue Type | Affected Versions | Fixed Version | CVSS |
|---|---|---|---|---|
|
CVE-2026-7641
Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privile...
|
Privilege Escalation | Versions up to 2.0.8 | 2.0.9 | CVSS 8.8 |
|
CVE-2019-15329
Import and export users and customers <= 1.14.0.2 - Cross-Site Request Forgery
|
Cross-Site Request Forgery | Versions before 1.14.0.3 | 1.14.0.3 | CVSS 8.8 |
|
CVE-2026-3629
Import and export users and customers <= 1.29.7 - Privilege Escalation to Administra...
|
Privilege Escalation | Versions up to 1.29.7 | 2.0 | CVSS 8.1 |
|
CVE-2022-3558
Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV In...
|
Vulnerability | Versions up to 1.20.4 | 1.20.5 | CVSS 8.0 |
|
CVE-2019-15326
Import and export users and customers <= 1.14.2.1 - Directory Traversal
|
Vulnerability | Versions up to 1.14.2.1 | 1.14.2.2 | CVSS 7.5 |
|
CVE-2020-22277
Import and export users and customers <= 1.16.3.5 - CSV injection via a customer's p...
|
Vulnerability | Versions up to 1.16.3.5 | 1.16.3.6 | CVSS 7.3 |
|
CVE-2024-32817
Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object...
|
Vulnerability | Versions up to 1.26.2 | 1.26.3 | CVSS 7.2 |
|
CVE-2023-6583
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Dire...
|
Vulnerability | Versions up to 1.24.2 | 1.24.3 | CVSS 6.6 |
Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields
Import and export users and customers <= 1.14.0.2 - Cross-Site Request Forgery
Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields
Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV Injection
Import and export users and customers <= 1.14.2.1 - Directory Traversal
Import and export users and customers <= 1.16.3.5 - CSV injection via a customer's profile
Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object Injection
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality
This hub clusters tracked records for Import and export users and customers so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` func...
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile...
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.27.12. This makes it possible for unaut...
Sorted by latest disclosure date so newly published issues surface first.
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys...
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile...
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.27.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.26.8 via the fileupload_process function that uploads an import file in a public directory and does not subsequently delete it. T...
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above...
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for au...
The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.26.2 via deserialization of untrusted input in the import.php file. This makes it possible for authenticated attackers, with administrator-...
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the fire_cron function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to trigge...
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This make...