Plugin Vulnerability Hub
Plugin 21 known issues Latest disclosed Mar 21, 2026

Import and export users and customers Vulnerabilities

Review known vulnerability records for the WordPress plugin Import and export users and customers (`import-users-from-csv-with-meta`), including severity, CVE references, affected versions, and patch status.

Known Records
21
High or Critical
7
Linked CVEs
20
Last Updated
Mar 21, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Import and export users and customers so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
21 records include a published patch path.
Severity Mix
0 critical and 7 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Import and export users and customers

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-3629
Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile...

Published
Mar 21, 2026
Patched Release
2.0
Affected Versions
Versions up to 1.29.7
Next Step
Update to 2.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-24689
Import and export users and customers <= 1.27.12 - Unauthenticated Sensitive Information Disclosure

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.27.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Published
Jan 27, 2025
Patched Release
1.27.13
Affected Versions
Versions up to 1.27.12
Next Step
Update to 1.27.13 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-50413
Import and export users and customers <= 1.27.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

Published
Oct 24, 2024
Patched Release
1.27.6
Affected Versions
Versions up to 1.27.5
Next Step
Update to 1.27.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-38787
Import and export users and customers <= 1.26.8 - Unauthenticated Information Exposure

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.26.8 via the fileupload_process function that uploads an import file in a public directory and does not subsequently delete it. T...

Published
Aug 07, 2024
Patched Release
1.26.9
Affected Versions
Versions up to 1.26.8
Next Step
Update to 1.26.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4734
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

Published
May 14, 2024
Patched Release
1.26.7
Affected Versions
Versions up to 1.26.6.1
Next Step
Update to 1.26.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4656
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...

Published
May 14, 2024
Patched Release
1.26.7
Affected Versions
Versions up to 1.26.6.1
Next Step
Update to 1.26.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-1050
Import and export users and customers <= 1.26.5 - Missing Authorization

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for au...

Published
May 03, 2024
Patched Release
1.26.6
Affected Versions
Versions up to 1.26.5
Next Step
Update to 1.26.6 or newer if supported.
Plugin High Patched: Yes CVE-2024-32817
Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object Injection

The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.26.2 via deserialization of untrusted input in the import.php file. This makes it possible for authenticated attackers, with administrator-...

Published
Apr 22, 2024
Patched Release
1.26.3
Affected Versions
Versions up to 1.26.2
Next Step
Update to 1.26.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-22151
Import and export users and customers <= 1.24.6 - Missing Authorization via fire_cron REST endpoint

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the fire_cron function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to trigge...

Published
Jan 16, 2024
Patched Release
1.24.7
Affected Versions
Versions up to 1.24.6
Next Step
Update to 1.24.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6624
Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This make...

Published
Dec 11, 2023
Patched Release
1.24.4
Affected Versions
Versions up to 1.24.3
Next Step
Update to 1.24.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6583
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to rea...

Published
Dec 08, 2023
Patched Release
1.24.3
Affected Versions
Versions up to 1.24.2
Next Step
Update to 1.24.3 or newer if supported.
Plugin High Patched: Yes CVE-2022-3558
Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV Injection

The Import and export users and customers plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.20.4. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are...

Published
Oct 17, 2022
Patched Release
1.20.5
Affected Versions
Versions up to 1.20.4
Next Step
Update to 1.20.5 or newer if supported.