CVE-2025-15673

Published Aug 3, 2026

Last updated 17 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-15673 identifies a vulnerability within the WordPress plugin "Import and Export Users and Customers," specifically affecting versions prior to 2.4.3. This flaw stems from the plugin's handling of file paths during CSV import operations. The vulnerability allows a privileged user to reference and display arbitrary files located on the server. This is possible because the plugin does not adequately restrict the paths of files that can be loaded and displayed during the CSV import process.

Description
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
Source
contact@wpscan.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.9
Impact score
3.6
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-22

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.