User Import Vulnerability in WooCommerce Plugin by WordPress
CVE-2020-12074
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 23 April 2020
What is CVE-2020-12074?
The users-customers-import-export-for-wp-woocommerce plugin for WordPress prior to version 1.3.9 has a potential security flaw that allows subscribers to import administrative account details through CSV files. This vulnerability could lead to unauthorized access, resulting in compromised administrative privileges for subscribers, thus posing a risk to site security.