CVE-2020-12074: Webtoffee Import Export WordPress Users
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
Affected products
- Webtoffee Import Export WordPress Users: before 1.3.9 (fixed in 1.3.9)
Published 2020-04-23. Last modified 2026-06-17.