CVE · Medium

CVE-2024-1050 — Import and export users and customers [import-users-from-csv-with-meta] < 1.26.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1050 Import and export users and customers [import-users-from-csv-with-meta] < 1.26.6 Missing Authorization Medium 4.3 < 1.26.6 1.26.6 2024-05-03

CVE-2024-1050

The Import and export users and customers plugin for WordPress contains a vulnerability in the ajax_force_reset_password_delete_metas() function that fails to verify user capabilities before allowing data modification. Authenticated users with subscriber-level permissions or higher can exploit this flaw to delete all forced password reset records. The issue affects plugin versions up to and including 1.26.5 and was remedied in version 1.26.6.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.