CVE-2019-15092: High severity webtoffee import export wordpress users vulnerability
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the userurl, displayname, firstname, and lastname columns in an exported CSV file created by the WFCustomerImpExpCsvExporter class.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2019-15092.
What is the severity of CVE-2019-15092?
The severity of CVE-2019-15092 is high with a CVSS score of 7.3.
What is the affected software for CVE-2019-15092?
The affected software for CVE-2019-15092 is the webtoffee WordPress Users & WooCommerce Customers Import Export plugin version 1.3.0 for WordPress.
How does CVE-2019-15092 work?
CVE-2019-15092 allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class of the webtoffee plugin.
Is there a fix available for CVE-2019-15092?
Yes, a fix is available in version 1.3.1 of the webtoffee WordPress Users & WooCommerce Customers Import Export plugin.