CVE Database /
CVE-2024-38787
CVE · High
CVE-2024-38787 — Import and export users and customers [import-users-from-csv-with-meta] < 1.26.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-38787
|
Import and export users and customers [import-users-from-csv-with-meta] < 1.26.9 |
Exposure of Sensitive Information to an Unauthorized Actor |
High
7.5
|
< 1.26.9
|
1.26.9 |
2024-08-07 |
—
|
CVE-2024-38787
The Import and export users and customers plugin for WordPress contains a sensitive information exposure vulnerability affecting versions 1.26.8 and earlier. The fileupload_process function stores imported files in a publicly accessible directory without removing them afterward, allowing unauthenticated attackers to access and retrieve sensitive user information from these unprotected uploads. The vulnerability was fixed in version 1.26.9.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings