6
CVSSv2

CVE-2019-15092

Published: 23/08/2019 Updated: 24/08/2020
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.3 | Impact Score: 5.9 | Exploitability Score: 1.3
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webtoffee import export wordpress users

Exploits

WordPress Import Export WordPress Users plugin version 131 suffers from a CSV injection vulnerability ...
# Exploit Title: Wordpress Plugin Import Export WordPress Users <= 131 - CSV Injection # Exploit Author: Javier Olmedo # Contact: @jjavierolmedo # Website: sidertiacom # Date: 2018-08-22 # Google Dork: inurl:"/wp-content/plugins/users-customers-import-export-for-wp-woocommerce" # Vendor: WebToffee # Software Link: downloadswo ...