Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Codection

First CVE: May 10, 2017Active for: 9 yearsTotal CVEs: 16
31.0
VTI Score
Low

Codection develops a small suite of WordPress plugins focused on user and customer data management, import utilities, and authentication, occupying a niche but measurable presence in the WordPress ecosystem. The vendor's vulnerability profile centers on input-handling and web-application weaknesses including cross-site scripting, cross-site request forgery, path traversal, PHP remote file inclusion, and CSV formula injection—a coherent pattern reflecting the data-import and form-processing attack surface of administrative plugins. Defenders running these plugins should prioritize updates and restrict administrative access; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Codection over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 10, 2017
9 years ago
Most Recent CVE
Aug 30, 2024
695 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-8252HIGH
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register sho
Aug 30, 20248.841NOYES
CVE-2019-15329HIGH
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
Aug 22, 20198.828NONO
CVE-2022-3558HIGH
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
Nov 7, 20228.026NONO
CVE-2020-22277HIGH
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
Nov 4, 20208.025NONO
CVE-2019-15326HIGH
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
Aug 22, 20197.524NONO
CVE-2023-6583HIGH
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functional
Jan 11, 20247.222NONO
CVE-2017-8875MEDIUM
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
May 10, 20176.522NONO
CVE-2019-15328MEDIUM
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
Aug 22, 20196.121NONO
CVE-2019-15327MEDIUM
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
Aug 22, 20196.121NONO
CVE-2019-14683MEDIUM
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
Aug 8, 20195.721NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
63%
38%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (25.0%)
Unknown0 (0.0%)
Required12 (75.0%)
Privileges Required
Low6 (37.5%)
High2 (12.5%)
None8 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.2% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Codection.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Codection — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Codection's Products

View all 4 CNAs →

Top CWEs