Access violation vulnerability in 6 plugins by webtoffee

The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before version 1.3.9 had a vulnerability that allowed people to upload a CSV file to create administrator accounts on a WordPress website.

Detected in:

Comments Import & Export fixed vulnerable versions:
Export and Import Users and Customers fixed vulnerable versions: >= * < 1.3.9
Order Export & Order Import for WooCommerce fixed vulnerable versions: >= * < 1.6.1
WordPress Comments Import & Export fixed vulnerable versions: >= * < 2.1.11
Order XML File Export Import for WooCommerce open vulnerable versions: >= * < 1.3.1
Product Reviews Import Export for WooCommerce open vulnerable versions: >= * < 1.3.3
XML File Export Import for Stamps.com and WooCommerce open vulnerable versions: >= * < 1.1.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.