Pricing
Case studies
Login
Start trial
Import and export users and customers
Javier Carazo
Developer
2.0.1
Latest version
80,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
18 patched
5 Mitigation rules
Privilege Escalation to Administrator via save_extra_user_profile_fields vulnerability
<= 1.29.7
24/03/2026
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 1.26.6.1
02/02/2026
Sensitive Data Exposure vulnerability
<= 1.27.12
27/01/2025
Cross Site Scripting (XSS) vulnerability
<= 1.27.5
24/10/2024
Sensitive Information via Imported File vulnerability
<= 1.26.8
07/08/2024
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 1.26.6.1
14/05/2024
Broken Access Control vulnerability
<= 1.26.5
09/05/2024
PHP Object Injection vulnerability
<= 1.26.2
22/04/2024
Broken Access Control vulnerability
<= 1.24.6
16/01/2024
Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode vulnerability
<= 1.24.3
11/12/2023
Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality vulnerability
<= 1.24.2
11/12/2023
Stored Cross-Site Scripting (XSS) vulnerability
<= 1.19.2
11/04/2022
CSV Injection vulnerability
<= 1.16.3.5
20/11/2020
Unauthorised Authenticated Users Export vulnerability
1.15
06/01/2020
Cross-Site Request Forgery (CSRF) vulnerability
<= 1.14.1.3
26/06/2019
Cross-Site Scripting (XSS) vulnerability
<= 1.12
13/12/2018
Authenticated Media Deletion Vulnerability
<= 1.9.4.6
02/09/2016
Cross-Site Request Forgery (CSRF)
<= 1.9.4.6
02/09/2016