CVE-2024-38787

Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.8.
Configurations

No configuration.

History

23 Apr 2026, 15:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

01 Apr 2026, 16:17

Type Values Removed Values Added
Summary
  • (es) La exposición de información confidencial a una vulnerabilidad de actor no autorizado en los usuarios y clientes de importación y exportación de Codection permite el acceso a la funcionalidad no restringida adecuadamente por las ACL. Este problema afecta a los usuarios y clientes de importación y exportación: desde n/a hasta 1.26.8.
Summary (en) Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8. (en) Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.8.
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : unknown
CWE CWE-200 CWE-201
References
  • {'url': 'https://patchstack.com/database/vulnerability/import-users-from-csv-with-meta/wordpress-import-and-export-users-and-customers-plugin-1-26-8-sensitive-information-via-imported-file-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/import-users-from-csv-with-meta/vulnerability/wordpress-import-and-export-users-and-customers-plugin-1-26-8-sensitive-information-via-imported-file-vulnerability?_s_id=cve -

13 Aug 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-13 11:15

Updated : 2026-04-23 15:18


NVD link : CVE-2024-38787

Mitre link : CVE-2024-38787

CVE.ORG link : CVE-2024-38787


JSON object : View

Products Affected

No product.

CWE
CWE-201

Insertion of Sensitive Information Into Sent Data