Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesImport and export users and customers

Import and export users and customers vulnerabilities

Import and export users and customers has 24 known vulnerabilities in this database. The most recent published record is dated 6 Oct 2026.

Known vulnerabilities
24
Active installs
70,000+
Latest version
2.5.5
Last updated
29 Sep 2026
Most recent
6 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Privilege escalation
CVE-2026-104757
High 7.2Up to 2.5.5No fixed version yet1 d ago
Privilege escalation
CVE-2026-86583
High 8.8Up to 2.4.17Fixed in a later version (latest 2.5.5)23 Sep 2026
Privilege escalation
CVE-2026-92540
High 7.2Before 2.5.2Fixed in 2.5.220 Sep 2026
Privilege escalation
CVE-2026-92541
High 7.2Before 2.5.2Fixed in 2.5.220 Sep 2026
Server-side request forgery (SSRF)
CVE-2026-16542
Medium 4.1Before 2.4.5Fixed in 2.4.520 Sep 2026
Privilege escalation
CVE-2026-16534
Critical 9.1Before 2.4.2Fixed in 2.4.23 Aug 2026
Path traversal
CVE-2025-15673
Medium 4.9Before 2.4.3Fixed in 2.4.33 Aug 2026
Sensitive data exposure
CVE-2026-15026
Medium 4.3Up to 2.4.0Fixed in a later version (latest 2.5.5)10 Jul 2026
Privilege escalation
CVE-2026-7641
High 8.8Up to 2.0.8Fixed in a later version (latest 2.5.5)2 May 2026
Privilege escalation
CVE-2026-3629
High 8.1Up to 1.29.7Fixed in a later version (latest 2.5.5)21 Mar 2026
Cross-site scripting (XSS)
CVE-2024-4734
Medium 4.4Up to 1.26.6.1Fixed in a later version (latest 2.5.5)15 May 2024
Cross-site scripting (XSS)
CVE-2024-4656
Medium 4.4Up to 1.26.6.1Fixed in a later version (latest 2.5.5)15 May 2024
Broken access control
CVE-2024-1050
Medium 4.3Up to 1.26.5Fixed in a later version (latest 2.5.5)4 May 2024
Cross-site scripting (XSS)
CVE-2023-6624
Medium 4.9Up to 1.24.3Fixed in a later version (latest 2.5.5)11 Jan 2024
Path traversal
CVE-2023-6583
Medium 6.6Up to 1.24.2Fixed in a later version (latest 2.5.5)11 Jan 2024
CSV injection
CVE-2022-3558
High 8.0Before 1.20.5Fixed in 1.20.57 Nov 2022
Cross-site scripting (XSS)
CVE-2022-1255
Medium 4.8Before 1.19.2.1Fixed in 1.19.2.12 May 2022
CSV injection
CVE-2020-22277
High 8.0Up to 1.15.5.11Fixed in a later version (latest 2.5.5)4 Nov 2020
Path traversal
CVE-2019-15326
High 7.5Before 1.14.2.1Fixed in 1.14.2.122 Aug 2019
Cross-site scripting (XSS)
CVE-2019-15327
Medium 6.1Before 1.14.1.3Fixed in 1.14.1.322 Aug 2019
Cross-site scripting (XSS)
CVE-2019-15328
Medium 6.1Before 1.14.0.3Fixed in 1.14.0.322 Aug 2019
Cross-site request forgery (CSRF)
CVE-2019-15329
High 8.8Before 1.14.0.3Fixed in 1.14.0.322 Aug 2019
Cross-site request forgery (CSRF)
CVE-2019-14683
Medium 5.7Before 1.14.2.2Fixed in 1.14.2.28 Aug 2019
Cross-site scripting (XSS)
CVE-2018-20101
Medium 6.1Before 1.12.1Fixed in 1.12.112 Dec 2018
Read the published descriptions
CVE-2026-104757, 6 Oct 2026
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions. CVE record
CVE-2026-86583, 23 Sep 2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with only a single delimiter argument, causing PHP's default backslash escape character to be applied instead; because the export column layout places display_name immediately before the role column and nickname immediately after, an attacker can store crafted values in those two profile fields - saved by WordPress core via the standard profile page - such that the escape mismatch causes the parser to merge the display_name cell into the role field and rebalance the column count via nickname, yielding administrator as the parsed role for their own row when it reaches the import_user function's add_role function. This makes it possible for authenticated attackers with Subscriber-level access or above to escalate their privileges to Administrator. Exploitation requires a site administrator to trigger the plugin's documented export re-import migration with both "Update existing users" and "Update roles for existing users" set to "yes". CVE record
CVE-2026-92540, 20 Sep 2026
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator. CVE record
CVE-2026-92541, 20 Sep 2026
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator. CVE record
CVE-2026-16542, 20 Sep 2026
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks. CVE record
CVE-2026-16534, 3 Aug 2026
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email. CVE record
CVE-2025-15673, 3 Aug 2026
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. CVE record
CVE-2026-15026, 10 Jul 2026
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including non-public CPTs such as WooCommerce orders and internal CRM records) by enumerating post IDs. The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template is appended to the URL, which is reachable by any authenticated user including Subscribers. CVE record
CVE-2026-7641, 2 May 2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g., `wp_capabilities`, `wp_user_level`) but fails to block the equivalent meta keys for any other subsite in a WordPress Multisite network (e.g., `wp_2_capabilities`, `wp_2_user_level`), allowing these keys to pass the `in_array()` check and be written directly to user meta via `update_user_meta()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator on any subsite within the Multisite network by submitting a crafted profile update to `/wp-admin/profile.php`. Exploitation requires that an administrator has previously imported a CSV file containing multisite-prefixed capability column headers and has enabled the 'Show fields in profile?' option, which causes those keys to be stored in the `acui_columns` option and exposed as editable fields on the user profile page. CVE record
CVE-2026-3629, 21 Mar 2026
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' method does not include sensitive meta keys such as 'wp_capabilities'. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator by submitting a crafted registration request that sets the 'wp_capabilities' meta key. The vulnerability can only be exploited if the "Show fields in profile" setting is enabled and a CSV with a wp_capabilities column header has been previously imported. CVE record
CVE-2024-4734, 15 May 2024
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
CVE-2024-4656, 15 May 2024
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-1050, 4 May 2024
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all forced password resets. CVE-2024-34815 is a duplicate of this issue. CVE record
CVE-2023-6624, 11 Jan 2024
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-6583, 11 Jan 2024
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information. CVE record
CVE-2022-3558, 7 Nov 2022
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files. CVE record
CVE-2022-1255, 2 May 2022
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues CVE record
CVE-2020-22277, 4 Nov 2020
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. CVE record
CVE-2019-15326, 22 Aug 2019
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. CVE record
CVE-2019-15327, 22 Aug 2019
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. CVE record
CVE-2019-15328, 22 Aug 2019
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. CVE record
CVE-2019-15329, 22 Aug 2019
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. CVE record
CVE-2019-14683, 8 Aug 2019
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF. CVE record
CVE-2018-20101, 12 Dec 2018
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell. CVE record

What to do if you run Import and export users and customers

If you run Import and export users and customers, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Import and export users and customers vulnerabilities

Free. We email you when a new vulnerability is published for Import and export users and customers, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support