Codection Import and export users and customers
cpe:2.3:a:codection:import_and_export_users_and_customers:*:*:*:*:wordpress:*:*
- <= 1.27.12
A vulnerability allowing the retrieval of embedded sensitive data has been identified in the Codection WordPress plugin 'Import and Export Users and Customers', versions prior to 1.27.12. This issue arises from the improper handling of sensitive information, which is inadvertently exposed through files or directories that are accessible externally.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, which could be used to exploit other weaknesses within the system.
Users of the affected WordPress plugin should update to version 1.27.13 or later. Patchstack users can enable auto-update for vulnerable plugins.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.