What the vulnerability does
01Description
Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.8.
Explanation of Vulnerability in Simple Terms
02Summary
The Import and export users and customers plugin for WordPress contains an information disclosure vulnerability in versions up to 1.26.8. An unauthenticated attacker can read sensitive data over the network without user interaction. The vulnerability exposes confidential information that should be restricted. Update to a version newer than 1.26.8 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the plugin without authentication or user interaction.
Potential impact on your site
04Site Impact
Confidential user or customer data may be exposed to anyone on the internet.
Conditions required to exploit
05Prerequisites
Network access to the affected WordPress site; no authentication required.
Key dates
06Disclosure timeline
August 13, 2024
CVE published
April 28, 2026
Record updated