Vulnerabilities > Webtoffee > Import Export Wordpress Users > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-11 CVE-2023-6558 Unrestricted Upload of File with Dangerous Type vulnerability in Webtoffee Import Export Wordpress Users
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8.
network
low complexity
webtoffee CWE-434
7.2
2023-07-18 CVE-2023-3459 Unspecified vulnerability in Webtoffee Import Export Wordpress Users
The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1.
network
low complexity
webtoffee
7.2