CVE-2019-14683: Codection Import Users From Csv With Meta
Medium severity, CVSS 5.7. EPSS: 0.7% chance of exploitation in the next 30 days.
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
Affected products
- Codection Import Users From Csv With Meta: before 1.14.2.2 (fixed in 1.14.2.2)
Published 2019-08-08. Last modified 2026-06-17.