Segurium Research Advisories import-users-from-csv-with-meta
Import and export users and customers 2.4.13 and earlier: Server-side request forgery
A remote server could redirect a CSV import in 2.4.13 to a cloud metadata endpoint or a private service, and the plugin followed that redirect without checking the new host. Version 2.4.14 replaces download_url() with a checked fetch.
- Plugin
- Import and export users and customers
import-users-from-csv-with-meta - Affected versions
- 2.4.13 and earlier
- Fixed in
2.4.14- Class
- Server-side request forgery
- Severity
- medium Segurium Research assessment. No CVSS score published yet.
- CVE
- None assigned at the time of writing
- Installs
- 70,000 active
- Patch released
- Sources