CVE-2024-32431
WordPress Import Users from CSV plugin <= 1.2 - PHP Object Injection
CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th
Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2.
| CWE | CWE-502 |
| Vendor | wp all import |
| Product | import users from csv |
| Published | Apr 15, 2024 |
| Last Updated | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for wp all import import users from csv
Be the first to know when new medium vulnerabilities affecting wp all import import users from csv are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
WP All Import / Import Users from CSV
n/a ≤ 1.2
References
Credits
Trình Vũ Sonicrrrr_ from VNPT-VCI (Patchstack Alliance)