PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15673 WordPress.org CVE debrief

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. This issue was reported by Wpscan. The vulnerability could allow an attacker to access sensitive information on the server. Defenders should verify plugin version and file access controls. Additional information may be needed to fully understand the vulnerability's impact. The evidence for this CVE is limited, and security teams should review the affected scope and severity of this vulnerability.

Vendor
WordPress.org
Product
Import and export users and customers
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-26
Advisory published
2026-08-03
Advisory updated
2026-08-26

Who should care

WordPress administrators using the Import and export users and customers plugin should be aware of this vulnerability and take necessary actions to protect their installations. This includes verifying the plugin version, restricting file access controls, and monitoring for potential security breaches. Additionally, security teams and vulnerability management teams should review the affected scope and severity of this vulnerability.

Technical summary

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict file paths during CSV imports, allowing high-privileged users to read arbitrary server files. This vulnerability could allow an attacker to access sensitive information on the server. The plugin's functionality allows high-privileged users to import CSV files, but it does not properly validate the file paths, leading to a potential security risk.

Defensive priority

Administrators of WordPress installations using the Import and export users and customers plugin should verify the plugin version and update to 2.4.3 or later if necessary.

Recommended defensive actions

  • Verify plugin version and update to 2.4.3 or later
  • Restrict file access controls for high-privileged users
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The evidence for this CVE is limited. The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. This issue was reported by Wpscan. Defenders should verify plugin version and file access controls. Additional information may be needed to fully understand the vulnerability's impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15673 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15673

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15673 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15673

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.