Import and export users and customers 1.15 - Sensitive Data Exposure

2020-01-01 00:00
Anonymous

Strategic Overview

Status
Patched in 1.15.0.1
Affected Version1.15
CVSS7.7High
CVEN/A
View all Import and export users and customers vulnerabilities

Vulnerability Overview

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 via the export_users_csv function. This can allow authenticated attackers to export user information even if they do not have account creation privileges. The function was introduced in this version and fixed in subsequent versions.

Technical Analysis

REMEDIATION: Update to version 1.15.0.1, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C