
Import and export users and customers Security & Risk Analysis
wordpress.org/plugins/import-users-from-csv-with-metaBulk import and export WordPress users and WooCommerce customers from CSV, including roles, passwords and any custom meta.
Is Import and export users and customers Safe to Use in 2026?
Generally Safe
Score 88/100Import and export users and customers has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "import-users-from-csv-with-meta" v2.0 plugin exhibits a mixed security posture. While the static analysis shows a good number of entry points are protected by authorization and nonce checks, several concerning code signals and historical vulnerability patterns warrant careful consideration. The presence of the "unserialize" function, even if not directly flagged as a critical taint flow, is a known risk for deserialization vulnerabilities if user-supplied data is ever passed to it without strict validation. The taint analysis revealing a high severity flow with unsanitized paths indicates a potential for serious security issues like path traversal or file inclusion if this flow is exploitable by an attacker.
The plugin's vulnerability history is a significant concern. With a total of 20 known CVEs, including a substantial number of high-severity issues, it suggests a recurring pattern of introducing security flaws. The breadth of vulnerability types, from sensitive information exposure and XSS to deserialization, RFI, and path traversal, points to a need for more robust secure coding practices throughout its development lifecycle. Although there are currently no unpatched CVEs, the sheer volume and variety of past vulnerabilities create an inherent risk and require vigilant monitoring and timely updates. The plugin's strengths lie in its protected entry points, but the identified code signals and historical context necessitate a cautious approach.
Key Concerns
- High severity taint flow found
- Use of 'unserialize' function
- Significant historical CVEs (20)
- Multiple high severity past CVEs (6)
- Many medium severity past CVEs (14)
- Low percentage of properly escaped output (62%)
- Unsanitized paths in taint flows (2)
Import and export users and customers Security Vulnerabilities
CVEs by Year
Severity Breakdown
24 total CVEs
Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action
Import and export users and customers <= 2.0.8 - Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields
Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields
Import and export users and customers <= 1.27.12 - Unauthenticated Sensitive Information Disclosure
Import and export users and customers <= 1.27.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Import and export users and customers <= 1.26.8 - Unauthenticated Information Exposure
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Import and export users and customers <= 1.26.5 - Missing Authorization
Import and export users and customers <= 1.26.5 - Missing Authorization
Import and export users and customers <= 1.26.2 - Authenticated (Admin+) PHP Object Injection
Import and export users and customers <= 1.24.6 - Missing Authorization via fire_cron REST endpoint
Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality
Import and export users and customers <= 1.20.4 - Authenticated (Subscriber+) CSV Injection
Import and export users and customers <= 1.19.2 - Stored Cross-Site Scripting
Import and export users and customers <= 1.16.3.5 - CSV injection via a customer's profile
Import and export users and customers 1.15 - Sensitive Data Exposure
Import and export users and customers <= 1.14.1.3 - Cross-Site Request Forgery leading to attachment deletion & Path Traversal
Import and export users and customers <= 1.14.2.1 - Directory Traversal
Import and export users and customers <= 1.14.1.2 - Cross-Site Scripting
Import and export users and customers <= 1.14.0.2 - Cross-Site Scripting
Import and export users and customers <= 1.14.0.2 - Cross-Site Request Forgery
Import users from CSV with meta <= 1.12 - Import Cross-Site Scripting
Import and export users and customers Release Timeline
Import and export users and customers Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Import and export users and customers Attack Surface
AJAX Handlers 14
REST API Routes 1
Shortcodes 3
WordPress Hooks 155
Maintenance & Trust
Import and export users and customers Maintenance & Trust
Maintenance Signals
Community Trust
Import and export users and customers Alternatives
Export and Import Users and Customers
users-customers-import-export-for-wp-woocommerce
Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.
Import Users from CSV
import-users-from-csv
Import users from a CSV into WordPress
Import Users & Customers with Meta | WP Ultimate CSV Importer Add-on
import-users
Bulk import WordPress users and WooCommerce customers with full user meta, custom fields, billing & shipping details, and membership data from CSV …
WP All Export – User Export Add-On
export-wp-users-xml-csv
Drag & drop to export users and all user data to a completely custom CSV, Excel, or XML of any format. Supports roles, metadata, custom fields, wi …
Export Users Data CSV
export-users-data-csv
Export Users Data Plugin allows you to export users information with important meta data in CSV file format.
Import and export users and customers Developer Profile
3 plugins · 71K total installs
How We Detect Import and export users and customers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-users-from-csv-with-meta/assets/style.css/wp-content/plugins/import-users-from-csv-with-meta/assets/script.js//cdn.datatables.net/2.2.2/js/dataTables.min.jsimport-users-from-csv-with-meta/assets/style.css?ver=import-users-from-csv-with-meta/assets/script.js?ver=HTML / DOM Fingerprints
acui-fielddata-user-idacui_js_object