CVE Database /
CVE-2024-34815
CVE · Medium
CVE-2024-34815 — Import and export users and customers [import-users-from-csv-with-meta] < 1.26.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-34815
|
Import and export users and customers [import-users-from-csv-with-meta] < 1.26.6 |
Missing Authorization |
Medium
5.4
|
< 1.26.6
|
1.26.6 |
2024-05-09 |
—
|
CVE-2024-34815
The Import and export users and customers plugin for WordPress contains a capability check vulnerability affecting versions 1.26.5 and earlier that allows authenticated users with minimal subscriber permissions to perform unauthorized actions. An attacker with basic access could exploit this missing validation to carry out operations they should not be permitted to execute. The vulnerability was patched in version 1.26.6.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings