HomeWordPress vulnerabilitiesImport and export users and customers
Import and export users and customers vulnerabilities
Import and export users and customers has 24 known vulnerabilities in this database. The most recent published record is dated 6 Oct 2026.
- Known vulnerabilities
- 24
- Active installs
- 70,000+
- Latest version
- 2.5.5
- Last updated
- 29 Sep 2026
- Most recent
- 6 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Privilege escalation CVE-2026-104757 | High 7.2 | Up to 2.5.5 | No fixed version yet | 1 d ago |
| Privilege escalation CVE-2026-86583 | High 8.8 | Up to 2.4.17 | Fixed in a later version (latest 2.5.5) | 23 Sep 2026 |
| Privilege escalation CVE-2026-92540 | High 7.2 | Before 2.5.2 | Fixed in 2.5.2 | 20 Sep 2026 |
| Privilege escalation CVE-2026-92541 | High 7.2 | Before 2.5.2 | Fixed in 2.5.2 | 20 Sep 2026 |
| Server-side request forgery (SSRF) CVE-2026-16542 | Medium 4.1 | Before 2.4.5 | Fixed in 2.4.5 | 20 Sep 2026 |
| Privilege escalation CVE-2026-16534 | Critical 9.1 | Before 2.4.2 | Fixed in 2.4.2 | 3 Aug 2026 |
| Path traversal CVE-2025-15673 | Medium 4.9 | Before 2.4.3 | Fixed in 2.4.3 | 3 Aug 2026 |
| Sensitive data exposure CVE-2026-15026 | Medium 4.3 | Up to 2.4.0 | Fixed in a later version (latest 2.5.5) | 10 Jul 2026 |
| Privilege escalation CVE-2026-7641 | High 8.8 | Up to 2.0.8 | Fixed in a later version (latest 2.5.5) | 2 May 2026 |
| Privilege escalation CVE-2026-3629 | High 8.1 | Up to 1.29.7 | Fixed in a later version (latest 2.5.5) | 21 Mar 2026 |
| Cross-site scripting (XSS) CVE-2024-4734 | Medium 4.4 | Up to 1.26.6.1 | Fixed in a later version (latest 2.5.5) | 15 May 2024 |
| Cross-site scripting (XSS) CVE-2024-4656 | Medium 4.4 | Up to 1.26.6.1 | Fixed in a later version (latest 2.5.5) | 15 May 2024 |
| Broken access control CVE-2024-1050 | Medium 4.3 | Up to 1.26.5 | Fixed in a later version (latest 2.5.5) | 4 May 2024 |
| Cross-site scripting (XSS) CVE-2023-6624 | Medium 4.9 | Up to 1.24.3 | Fixed in a later version (latest 2.5.5) | 11 Jan 2024 |
| Path traversal CVE-2023-6583 | Medium 6.6 | Up to 1.24.2 | Fixed in a later version (latest 2.5.5) | 11 Jan 2024 |
| CSV injection CVE-2022-3558 | High 8.0 | Before 1.20.5 | Fixed in 1.20.5 | 7 Nov 2022 |
| Cross-site scripting (XSS) CVE-2022-1255 | Medium 4.8 | Before 1.19.2.1 | Fixed in 1.19.2.1 | 2 May 2022 |
| CSV injection CVE-2020-22277 | High 8.0 | Up to 1.15.5.11 | Fixed in a later version (latest 2.5.5) | 4 Nov 2020 |
| Path traversal CVE-2019-15326 | High 7.5 | Before 1.14.2.1 | Fixed in 1.14.2.1 | 22 Aug 2019 |
| Cross-site scripting (XSS) CVE-2019-15327 | Medium 6.1 | Before 1.14.1.3 | Fixed in 1.14.1.3 | 22 Aug 2019 |
| Cross-site scripting (XSS) CVE-2019-15328 | Medium 6.1 | Before 1.14.0.3 | Fixed in 1.14.0.3 | 22 Aug 2019 |
| Cross-site request forgery (CSRF) CVE-2019-15329 | High 8.8 | Before 1.14.0.3 | Fixed in 1.14.0.3 | 22 Aug 2019 |
| Cross-site request forgery (CSRF) CVE-2019-14683 | Medium 5.7 | Before 1.14.2.2 | Fixed in 1.14.2.2 | 8 Aug 2019 |
| Cross-site scripting (XSS) CVE-2018-20101 | Medium 6.1 | Before 1.12.1 | Fixed in 1.12.1 | 12 Dec 2018 |
Read the published descriptions
- CVE-2026-104757, 6 Oct 2026
- Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions. CVE record
- CVE-2026-86583, 23 Sep 2026
- The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with only a single delimiter argument, causing PHP's default backslash escape character to be applied instead; because the export column layout places display_name immediately before the role column and nickname immediately after, an attacker can store crafted values in those two profile fields - saved by WordPress core via the standard profile page - such that the escape mismatch causes the parser to merge the display_name cell into the role field and rebalance the column count via nickname, yielding administrator as the parsed role for their own row when it reaches the import_user function's add_role function. This makes it possible for authenticated attackers with Subscriber-level access or above to escalate their privileges to Administrator. Exploitation requires a site administrator to trigger the plugin's documented export re-import migration with both "Update existing users" and "Update roles for existing users" set to "yes". CVE record
- CVE-2026-92540, 20 Sep 2026
- The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator. CVE record
- CVE-2026-92541, 20 Sep 2026
- The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator. CVE record
- CVE-2026-16542, 20 Sep 2026
- The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks. CVE record
- CVE-2026-16534, 3 Aug 2026
- The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email. CVE record
- CVE-2025-15673, 3 Aug 2026
- The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. CVE record
- CVE-2026-15026, 10 Jul 2026
- The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including non-public CPTs such as WooCommerce orders and internal CRM records) by enumerating post IDs. The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template is appended to the URL, which is reachable by any authenticated user including Subscribers. CVE record
- CVE-2026-7641, 2 May 2026
- The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g., `wp_capabilities`, `wp_user_level`) but fails to block the equivalent meta keys for any other subsite in a WordPress Multisite network (e.g., `wp_2_capabilities`, `wp_2_user_level`), allowing these keys to pass the `in_array()` check and be written directly to user meta via `update_user_meta()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator on any subsite within the Multisite network by submitting a crafted profile update to `/wp-admin/profile.php`. Exploitation requires that an administrator has previously imported a CSV file containing multisite-prefixed capability column headers and has enabled the 'Show fields in profile?' option, which causes those keys to be stored in the `acui_columns` option and exposed as editable fields on the user profile page. CVE record
- CVE-2026-3629, 21 Mar 2026
- The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' method does not include sensitive meta keys such as 'wp_capabilities'. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator by submitting a crafted registration request that sets the 'wp_capabilities' meta key. The vulnerability can only be exploited if the "Show fields in profile" setting is enabled and a CSV with a wp_capabilities column header has been previously imported. CVE record
- CVE-2024-4734, 15 May 2024
- The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
- CVE-2024-4656, 15 May 2024
- The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-1050, 4 May 2024
- The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all forced password resets. CVE-2024-34815 is a duplicate of this issue. CVE record
- CVE-2023-6624, 11 Jan 2024
- The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-6583, 11 Jan 2024
- The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information. CVE record
- CVE-2022-3558, 7 Nov 2022
- The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files. CVE record
- CVE-2022-1255, 2 May 2022
- The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues CVE record
- CVE-2020-22277, 4 Nov 2020
- Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. CVE record
- CVE-2019-15326, 22 Aug 2019
- The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. CVE record
- CVE-2019-15327, 22 Aug 2019
- The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. CVE record
- CVE-2019-15328, 22 Aug 2019
- The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. CVE record
- CVE-2019-15329, 22 Aug 2019
- The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. CVE record
- CVE-2019-14683, 8 Aug 2019
- The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF. CVE record
- CVE-2018-20101, 12 Dec 2018
- The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell. CVE record
What to do if you run Import and export users and customers
If you run Import and export users and customers, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Import and export users and customers vulnerabilities
Free. We email you when a new vulnerability is published for Import and export users and customers, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.