PT-2024-16320 · WordPress · Export/Import Users/Customers
Francesco Carlucci
·
Published
2024-05-03
·
Updated
2024-05-06
·
CVE-2024-1050
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Import and export users and customers plugin for WordPress versions up to, and including, 1.26.5
Description
The issue is related to a missing capability check on the
ajax force reset password delete metas() function, allowing authenticated attackers with subscriber-level access and above to delete all forced password resets. This enables unauthorized modification of data.Recommendations
For versions up to, and including, 1.26.5, update the plugin to a version higher than 1.26.5 to resolve the issue. As a temporary workaround, consider disabling the
ajax force reset password delete metas() function until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation. Review user accounts for suspicious activity after updating the plugin.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Export/Import Users/Customers