First published: Thu Aug 08 2019(Updated: )
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Codection Import Users From Csv With Meta | <1.14.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-14683.
The plugin affected by this vulnerability is Codection Import Users From Csv With Meta.
The severity of CVE-2019-14683 is medium with a severity value of 5.7.
To fix the vulnerability in Codection Import Users From Csv With Meta, update the plugin to version 1.14.2.2 or later.
You can find more information about CVE-2019-14683 in the references provided: https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta?rev=2112013, https://wordpress.org/plugins/import-users-from-csv-with-meta/#developers, and https://wpvulndb.com/vulnerabilities/9392.