What the vulnerability does
01Description
Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5.
Explanation of Vulnerability in Simple Terms
02Summary
The Import and export users and customers plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to modify or delete data they should not have access to. An attacker with a basic user account can alter user records or remove customer information without proper permission checks. Update to a version newer than 1.26.5 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify or delete user and customer records without proper authorization.
Potential impact on your site
04Site Impact
User and customer data can be altered or deleted by unauthorized accounts, risking data integrity and customer trust.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site (e.g., subscriber or customer role).
Key dates
06Disclosure timeline
June 11, 2024
CVE published
April 28, 2026
Record updated