Import and export users and customers 1.15 - Sensitive Data Exposure
2020-01-01 00:00
AnonymousStrategic Overview
StatusPatched in 1.15.0.1
Affected PluginImport and export users and customers
Affected Version
1.15CVSS7.7High
CVE
N/AVulnerability Overview
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 via the export_users_csv function. This can allow authenticated attackers to export user information even if they do not have account creation privileges. The function was introduced in this version and fixed in subsequent versions.
Technical Analysis
REMEDIATION: Update to version 1.15.0.1, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C