Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Webtoffee Subscribe
Filtered by product Import Export Wordpress Users
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-12074 1 Webtoffee 1 Import Export Wordpress Users 2021-07-21 6.5 MEDIUM 8.8 HIGH
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
CVE-2019-15092 1 Webtoffee 1 Import Export Wordpress Users 2020-08-24 6.0 MEDIUM 7.3 HIGH
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.