CVE-2018-20101

NONE EPSS 51.4%
Published Dec 12, 20187y ago ยท Modified Jun 17, 20262w ago
Find Similar
Published Dec 12, 2018 7y ago
Last Modified Jun 17, 2026 2w ago

Description

The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

Threat Intelligence

EPSS Exploit Probability
51.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-79 Cross-site Scripting Injection

Affected Products 1

VendorProductVersionRange
codectionimport_users_from_csv_with_meta1.12.1any

References 2

  • wordpress.org https://wordpress.org/plugins/import-users-from-csv-with-meta/#developers
    ProductRelease Notes
  • wpvulndb.com https://wpvulndb.com/vulnerabilities/9176

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.