Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Clean Login HIGH 8.8
CVE-2024-8252

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute …

Fix: 1.14.6+
Fix from $1,950 2024-08-30
Import And Export Users And Customers MEDIUM 5.3
CVE-2024-22151

Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from…

Fix: 1.24.7+
Fix from $1,600 2024-06-08
Import And Export Users And Customers MEDIUM 5.4
CVE-2023-6624

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all vers…

Fix: after 1.24.3
Fix from $1,600 2024-01-11
Import And Export Users And Customers HIGH 7.2
CVE-2023-6583

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via …

Fix: after 1.24.2
Fix from $1,950 2024-01-11
Clean Login MEDIUM 5.4
CVE-2022-4838

The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page,…

Fix: 1.13.7+
Fix from $1,600 2023-02-06
Import And Export Users And Customers HIGH 8.0
CVE-2022-3558

The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.

Fix: 1.20.5+
Fix from $1,950 2022-11-07
Import And Export Users And Customers HIGH 8.0
CVE-2020-22277

Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

Fix: after 1.15.5.11
Fix from $1,950 2020-11-04
Import Users From Csv With Meta HIGH 8.8
CVE-2019-15329

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

Fix: 1.14.0.3+
Fix from $1,950 2019-08-22
Import Users From Csv With Meta HIGH 7.5
CVE-2019-15326

The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

Fix: 1.14.2.1+
Fix from $1,950 2019-08-22
Import Users From Csv With Meta MEDIUM 6.1
CVE-2019-15327

The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

Fix: 1.14.1.3+
Fix from $1,600 2019-08-22
Import Users From Csv With Meta MEDIUM 6.1
CVE-2019-15328

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

Fix: 1.14.0.3+
Fix from $1,600 2019-08-22
Clean Login MEDIUM 6.1
CVE-2015-9336

The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

Fix: 1.5.1+
Fix from $1,600 2019-08-22
Import Users From Csv With Meta MEDIUM 5.7
CVE-2019-14683

The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSR…

Fix: 1.14.2.2+
Fix from $1,600 2019-08-08
Import Users From Csv With Meta MEDIUM 6.1
CVE-2018-20101

The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

Mitigation only
Fix from $1,600 2018-12-12
Clean Login MEDIUM 6.5
CVE-2017-8875

CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.

Patch available
Fix from $1,600 2017-05-10