Unauthorized Data Modification in WordPress Export and Import Users and Customers Plugin
CVE-2023-3459
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 July 2023
What is CVE-2023-3459?
The Export and Import Users and Customers plugin for WordPress has a security flaw allowing authenticated users with shop manager-level permissions to exploit the 'hf_update_customer' function through an AJAX action. This vulnerability enables attackers to bypass capability checks, modify user passwords, and potentially compromise administrator accounts. It is essential for website owners to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Export and Import Users and Customers * <= 2.4.1