Dismissed
(no matching packages found)
Activity log
- Created & dismissed (no matching packages found) suggestion
Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
References
-
https://wpscan.com/vulnerability/b1cf540a-1249-4f51-b9a3-804c77ebfd24/ exploitvdb-entrytechnical-description
Affected products
Import and export users and customers
- <2.4.3