CVE-2019-15092: Webtoffee Import Export WordPress Users

High severity, CVSS 7.3. EPSS: 5.1% chance of exploitation in the next 30 days.

The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.

Affected products

  • Webtoffee Import Export WordPress Users: up to and including 1.3.1

Published 2019-08-23. Last modified 2026-06-17.