CVE-2024-22151 MEDIUM

CVE-2024-22151: WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability

Vendor Codection
Product Import and export users and customers
Weakness CWE-862 · Missing authorization
Published June 8, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.

Explanation of Vulnerability in Simple Terms

02Summary

The Import and export users and customers plugin for Codection versions up to 1.24.6 lacks proper authorization checks on certain functions. An attacker without authentication can modify user or customer data through direct requests. The vulnerability does not expose sensitive information but allows unauthorized changes to records in the system.

What an attacker can do

03Attacker Capabilities

Modify user or customer data without logging in.

Potential impact on your site

04Site Impact

Attackers can alter user and customer records, potentially disrupting data integrity and user accounts.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 8, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE