CVE-2023-3459: Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change
The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hfupdatecustomer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop manager-level permissions to change user passwords and potentially take over administrator accounts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3459?
CVE-2023-3459 is a vulnerability in the Export and Import Users and Customers plugin for WordPress that allows authenticated attackers to modify data without proper authorization.
How does CVE-2023-3459 impact WordPress?
CVE-2023-3459 impacts WordPress by allowing authenticated attackers to modify data without proper authorization.
What is the severity of CVE-2023-3459?
The severity of CVE-2023-3459 is high, with a severity score of 7.2.
How can I fix CVE-2023-3459?
To fix CVE-2023-3459, update the Export and Import Users and Customers plugin for WordPress to a version higher than 2.4.1.
Where can I find more information about CVE-2023-3459?
You can find more information about CVE-2023-3459 at the following references: [Reference 1](https://plugins.trac.wordpress.org/changeset/2938705/users-customers-import-export-for-wp-woocommerce#file201), [Reference 2](https://plugins.trac.wordpress.org/browser/users-customers-import-export-for-wp-woocommerce/tags/2.4.1/admin/modules/user/import/import.php#L446), [Reference 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/47337214-9cc3-4b12-bb71-9acbab3649b7?source=cve).