Codection develops a small suite of WordPress plugins focused on user and customer data management, import utilities, and authentication, occupying a niche but measurable presence in the WordPress ecosystem. The vendor's vulnerability profile centers on input-handling and web-application weaknesses including cross-site scripting, cross-site request forgery, path traversal, PHP remote file inclusion, and CSV formula injection—a coherent pattern reflecting the data-import and form-processing attack surface of administrative plugins. Defenders running these plugins should prioritize updates and restrict administrative access; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codection over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8252HIGH The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register sho | Aug 30, 2024 | 8.8 | 41 | NO | YES |
CVE-2019-15329HIGH The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. | Aug 22, 2019 | 8.8 | 28 | NO | NO |
CVE-2022-3558HIGH The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files. | Nov 7, 2022 | 8.0 | 26 | NO | NO |
CVE-2020-22277HIGH Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. | Nov 4, 2020 | 8.0 | 25 | NO | NO |
CVE-2019-15326HIGH The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. | Aug 22, 2019 | 7.5 | 24 | NO | NO |
CVE-2023-6583HIGH The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functional | Jan 11, 2024 | 7.2 | 22 | NO | NO |
CVE-2017-8875MEDIUM CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL. | May 10, 2017 | 6.5 | 22 | NO | NO |
CVE-2019-15328MEDIUM The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. | Aug 22, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-15327MEDIUM The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. | Aug 22, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-14683MEDIUM The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF. | Aug 8, 2019 | 5.7 | 21 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codection.
Media articles that mention a CVE ID that affects a product developed by Codection — matched by CVE ID, not by vendor name.