← Back

Customizer Export/import

customizer_export/import

Vendor: Fastlinemedia • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fastlinemedia
1Customizer Export/import
Jul 10, 2025
Sep 7, 2024
N/A· v4
6.6 MEDIUM· v3
N/A· v2
The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and including, 0.9.7. This makes it possible...Show more
The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and including, 0.9.7. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: This vulnerability is only exploitable when used in conjunction with a race condition as the uploaded file is deleted shortly after it is created.Show less
1Fastlinemedia
1Customizer Export/import
Feb 4, 2025
May 8, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is...Show more
The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is presentShow less
2Fastlinemedia
Wpbeaverbuilder
2Customizer Export/import
Customizer Export/import
Mar 27, 2026
Oct 31, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a...Show more
The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.Show less