Vulnerability Details: Information Disclosure in Export Users to CSV
The latest version of the plugin Export Users to CSV doesn’t have a changelog, which it turns out is not the only issue with it. The Subversion commit for the new version does have a log entry and that is “Security Updates”. Looking at the changes made in that version we found that previously the plugin saved files with the WordPress users data in a way that an attacker might be able to access.
…