CVE-2026-7641
Import and export users and customers
Minimum safe version
2.0.9
Update to 2.0.9 or later to address 28 fixable vulnerabilities
Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields
CVE-2025-24689
CVE-2024-50413
CVE-2024-38787
CVE-2024-4656
CVE-2024-4734
CVE-2024-34815
CVE-2024-1050
CVE-2024-32817
CVE-2024-22151
CVE-2023-6624
CVE-2023-6583
Import Users From CSV with Meta 1.15 - Unauthorised Authenticated Users Export
Import and export users and customers 1.15 - Sensitive Data Exposure
CVE-2022-3558
WordPress Import users from CSV with meta Plugin <= 1.9.4.6 - Cross-Site Request Forgery (CSRF)
WordPress Import users from CSV with meta plugin <= 1.9.4.6 - Authenticated Media Deletion Vulnerability
WordPress Import users from CSV with meta plugin <= 1.14.1.3 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Import Users From CSV with Meta plugin 1.15 - Unauthorised Authenticated Users Export vulnerability
CVE-2022-1255
WordPress Import users from CSV with meta plugin <= 1.12 - Cross-Site Scripting (XSS) vulnerability
CVE-2019-14683
CVE-2019-15326
CVE-2019-15329
CVE-2019-15328
CVE-2019-15327
WordPress Import and export users and customers plugin <= 1.16.3.5 - CSV Injection vulnerability