Import and export users and customers

Explore Import and export users and customers vulnerabilities across all versions. Currently tracking 24 known vulnerabilities, including severity, impact, and patch status.

01234567891014.07.2014Today11.12.20186.1Import users from CSV with meta <= 1.12 - Import Cross-Site Scripting CVSS 6.1 · 11.12.201814.03.20198.8Import and export users and customers <= 1.14.0.2 - Cross-Site Request Forgery CVSS 8.8 · 14.03.20196.1Import and export users and customers <= 1.14.0.2 - Cross-Site Scripting CVSS 6.1 · 14.03.201920.06.20197.5Import and export users and customers <= 1.14.2.1 - Directory Traversal CVSS 7.5 · 20.06.20196.1Import and export users and customers <= 1.14.1.2 - Cross-Site Scripting CVSS 6.1 · 20.06.201922.06.20196.3Import and export users and customers <= 1.14.1.3 - Cross-Site Request Forgery leading to attachment deletion & Path Traversal CVSS 6.3 · 22.06.201901.01.20207.7Import and export users and customers 1.15 - Sensitive Data Exposure CVSS 7.7 · 01.01.202020.11.20207.3Import and export users and customers <= 1.16.3.5 - CSV injection via a customer's profile CVSS 7.3 · 20.11.202011.04.20225.5Import and export users and customers <= 1.19.2 - Stored Cross-Site Scripting CVSS 5.5 · 11.04.202217.10.20228.0Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV Injection CVSS 8.0 · 17.10.202208.12.20236.6Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality CVSS 6.6 · 08.12.202311.12.20234.9Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode CVSS 4.9 · 11.12.202316.01.20245.3Import and export users and customers <= 1.24.6 - Missing Authorization via fire_cron REST endpoint CVSS 5.3 · 16.01.202422.04.20247.2Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object Injection CVSS 7.2 · 22.04.202403.05.20244.3Import and export users and customers <= 1.26.5 - Missing Authorization CVSS 4.3 · 03.05.202409.05.20244.3Import and export users and customers <= 1.26.5 - Missing Authorization CVSS 4.3 · 09.05.202414.05.20244.4Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 14.05.20244.4Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 14.05.202407.08.20245.3Import and export users and customers <= 1.26.8 - Unauthenticated Information Exposure CVSS 5.3 · 07.08.202424.10.20244.4Import and export users and customers <= 1.27.5 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 24.10.202427.01.20255.3Import and export users and customers <= 1.27.12 - Unauthenticated Sensitive Information Disclosure CVSS 5.3 · 27.01.202521.03.20268.1Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields CVSS 8.1 · 21.03.202601.05.20268.8Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields CVSS 8.8 · 01.05.202609.07.20264.3Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action CVSS 4.3 · 09.07.2026

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

24

Get automatic notifications for all Import and export users and customers vulnerabilities before they are exploited.

Vulnerability Records

24 records
2026-07-09 19:58CVE-2026-15026
4.3
Medium
Tiago Ventura (perses)Yes
2026-05-01 16:14CVE-2026-7641
8.8
High
kiemtiendinhauYes
2026-03-21 10:03CVE-2026-3629
8.1
High
kai63001Yes
2025-01-27 00:00CVE-2025-24689
5.3
Medium
Caesar Evan SantosoYes
2024-10-24 00:00CVE-2024-50413
4.4
Medium
UKOYes
2024-08-07 00:00CVE-2024-38787
5.3
Medium
emadYes
2024-05-14 12:08CVE-2024-4734
4.4
Medium
quanhxYes
2024-05-14 12:07CVE-2024-4656
4.4
Medium
quanhxYes
2024-05-09 00:00CVE-2024-34815
4.3
Medium
emadYes
2024-05-03 00:00CVE-2024-1050
4.3
Medium
Francesco CarlucciYes
Showing 1–10 of 24 reports
Import and export users and customers banner
Latestv2.4.8

Import and export users and customers

Javier Carazo

Author

Javier Carazo

4.7(256)
94/100
Last Updated
2026-07-29 (10h ago)
Active Installs
70,000+
Downloads
6,323,292
Requires WP
5.5+
Requires PHP
0+
Tested up to
WP 7.0.2
Created
2014-07-14 (12y ago)

Try it out on your free dummy site: Click here => https://demo.tastewp.com/import-users-from-csv-with-meta Import, export and migrate WordPress users and WooCommerce customers from a CSV file. Bulk-create or update thousands of users in seconds, schedule automatic recurring imports from a local file or URL, and carry over roles, passwords and any custom meta field. Works with WooCommerce, BuddyPress, Advanced Custom Fields, Paid Membership Pro, WooCommerce Memberships, WooCommerce Subscriptions and many more. Import CSV file with users directly to your WordPress or customers into WooCommerce Import thousands of users or customers in only some seconds Export users or customers to a CSV file, filtering by role or registered date You can also import meta-data like data from WooCommerce customers You can assign roles while importing. Send a mail to every new user, this mails can be saved as templates and are fully customizable, before sending you can test it You can also update users if the user is already in your WordPress Create a cron task to import users periodically Edit the metadata (you will be able to edit the metadata imported using metakeys directly in the profile of each user) Extend the plugin using the hooks we provide Compatible with WPML read the documentation to see how you can translate the front-end import and export users page and send translated email notifications to users Moreover this plugin is compatible with many other plugins to be able to import and include them data, subscriptions, memberships, etc. Take a look: WooCommerce: to import the customer data WooCommerce Memberships: to import memberships WooCommerce Subscriptions: to create subscriptions associated with users while they are being imported BuddyPress: to import custom BuddyPress avatars, fields, groups and roles Advanced Custom Fields: to import data to the fields you define there Paid Membership Pro: to import memberships, included compatibility with PMPro version 3 Indeed Ultimate Membership Pro: to import memberships Paid Member Subscriptions: to import memberships Allow Multiple Accounts: plugin will allow the same rules importing than this plugin Groups: to assign users to groups while importing New User Approve: you can import users and approbe/wait for approve them Users Group: to assign users to groups while importing WP LMS Course: to enroll users in the courses while importing WP Members: to import memberships WP Users Group: to assign users to groups while importing WooCommerce Membership by RightPress: to create memberships while users are being imported WP Private Content Plus: To import and export the groups to which users are assigned If you have some problem or doubt: Read our documentation Ask anything in support forum, we try to give the best support Common use cases Migrate users from one WordPress site to another Bulk create or update WooCommerce customers from a spreadsheet Sync users automatically from an external CRM or ERP via CSV Onboard members to a membership site (Paid Membership Pro, WooCommerce Memberships) Periodically import subscribers or students from an external list Import users from the frontend using a shortcode Usage Once the plugin is installed you can use it. Go to Tools menu and there, there will be a section called Insert users from CSV. Just choose your CSV file and go! CSV generation You can generate CSV file with all users inside it, using a standar spreadsheet software like: Microsoft Excel, LibreOffice Calc, OpenOffice Calc or Gnumeric. You have to create the file filled with information (or take it from another database) and you will only have to choose CSV file when you “Save as…” the file. As example, a CSV file is included with the plugin. Some considerations Plugin will automatically detect: Charset and set it to UTF-8 to prevent problems with non-ASCII characters. It also will auto detect line-ending to prevent problems with different OS. Finally, it will detect the delimiter being used in CSV file Other plugins by Codection RedSys Gateway for WooCommerce Pro (premium) Ceca Gateway for WooCommerce Pro (premium) RedSys Gateway for Contact Form 7 (premium) Ceca Gateway for Contact Form 7 (premium) RedSys & Bizum Gateway for Gravity Forms (premium) RedSys & Bizum Gateway for WPForms (premium) RedSys & Bizum for GiveWP (premium) RedSys Link Generator (premium) RedSys & Bizum Gateway for EDD Pro (premium) RedSys Gateway for WP Booking Calendar Pro (premium) Clean Login (free) Products Restricted Users for WooCommerce (free) First payment date for WooCommerce Subscriptions (free) Payment Schedule for WooCommerce Subscriptions (premium)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C