CVE-2022-3558

HIGH

WordPress Plugin <1.20.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.

Scores

CVSS v3 8.0
EPSS 0.0080
EPSS Percentile 74.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-1236
Status published
Products (1)
codection/import_and_export_users_and_customers < 1.20.5
Published Nov 07, 2022
Tracked Since Feb 18, 2026