AI description
CVE-2025-15673 identifies a vulnerability within the WordPress plugin "Import and Export Users and Customers," specifically affecting versions prior to 2.4.3. This flaw stems from the plugin's handling of file paths during CSV import operations. The vulnerability allows a privileged user to reference and display arbitrary files located on the server. This is possible because the plugin does not adequately restrict the paths of files that can be loaded and displayed during the CSV import process.
- Description
- The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
- Source
- contact@wpscan.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 4.9
- Impact score
- 3.6
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-22
- Hype score
- Not currently trending
🚨*CVE* CVE-2025-15673 The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-… https://t.co/vGy6faH12R ----- Traducción: CVE-2025-15673 El … https://t.co/utmtNg
@infoflowcloud
3 Aug 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15673 The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-… https://t.co/TeR0bXNugj
@CVEnew
3 Aug 2026
1350 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes