First published: Mon Apr 15 2024(Updated: )
Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP All Import | <=1.2 | |
WordPress Import Users from CSV | <=1.2 |
Update to 1.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32431 is categorized as a critical severity vulnerability due to the potential for remote code execution.
To fix CVE-2024-32431, users should update the WP All Import Import Users from CSV plugin to the latest version beyond 1.2.
CVE-2024-32431 is a deserialization of untrusted data vulnerability.
CVE-2024-32431 affects WP All Import Import Users from CSV versions up to and including 1.2.
The impact of CVE-2024-32431 could allow an attacker to execute arbitrary code on the affected system.