Cross-Site Request Forgery Vulnerability in Import Users from CSV with Meta Plugin for WordPress
CVE-2019-14683
5.7MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 8 August 2019
What is CVE-2019-14683?
The Import Users from CSV with Meta plugin for WordPress prior to version 1.14.2.2 is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to exploit wp-admin/admin-ajax.php?action=acui_delete_attachment. This exploit can enable unauthorized actions without the user's consent, potentially leading to the deletion of media attachments.