CVE-2022-1255

CVE-2022-1255: Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting

Vendor Unknown
Product Import and export users and customers
Weakness CWE-79 · XSS
Published May 2, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues

Key dates

02Disclosure timeline

May 2, 2022 CVE published
August 2, 2024 Record updated