CVE-2019-14683
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
08/08/2019
Last modified:
24/02/2023
Description
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
Impact
Base Score 3.x
5.70
Severity 3.x
MEDIUM
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:codection:import_users_from_csv_with_meta:*:*:*:*:*:wordpress:*:* | 1.14.2.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta?rev=2112013
- https://wordpress.org/plugins/import-users-from-csv-with-meta/#developers
- https://wpvulndb.com/vulnerabilities/9392
- https://www.pluginvulnerabilities.com/2019/06/21/cross-site-request-forgery-csrf-media-deletion-vulnerability-in-import-users-from-csv-with-meta/



