Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw98-5fp3-v7vg

Опубликовано: 03 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.

EPSS

Процентиль: 3%
0.00132
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-269

EPSS

Процентиль: 3%
0.00132
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-269