Vulnerabilities > Codection > Import Users From CSV With Meta > 1.14.2.1

DATE CVE VULNERABILITY TITLE RISK
2019-08-08 CVE-2019-14683 Cross-Site Request Forgery (CSRF) vulnerability in Codection Import Users From CSV With Meta
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
network
low complexity
codection CWE-352
5.7