SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2025-15673

MEDIUM · CVSS 4.9 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Import and Export Users and Customers plugin for WordPress versions prior to 2.4.3 is vulnerable due to inadequate path restrictions during CSV imports, enabling high-privileged users to access arbitrary files on the server. This could lead to unauthorized disclosure of sensitive information, potentially compromising the integrity and confidentiality of the server. WordPress administrators and security teams should prioritize updating this plugin to mitigate the risk of exploitation.

CVE
CVE-2025-15673
Severity
MEDIUM
CVSS
4.9
EPSS
0.34%
WordPress

Original NVD Description

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.