PatchSiren cyber security CVE debrief
CVE-2025-15673 WordPress.org CVE debrief
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. This issue was reported by Wpscan. The vulnerability could allow an attacker to access sensitive information on the server. Defenders should verify plugin version and file access controls. Additional information may be needed to fully understand the vulnerability's impact. The evidence for this CVE is limited, and security teams should review the affected scope and severity of this vulnerability.
- Vendor
- WordPress.org
- Product
- Import and export users and customers
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-08-03
Who should care
WordPress administrators using the Import and export users and customers plugin should be aware of this vulnerability and take necessary actions to protect their installations. This includes verifying the plugin version, restricting file access controls, and monitoring for potential security breaches. Additionally, security teams and vulnerability management teams should review the affected scope and severity of this vulnerability.
Technical summary
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict file paths during CSV imports, allowing high-privileged users to read arbitrary server files. This vulnerability could allow an attacker to access sensitive information on the server. The plugin's functionality allows high-privileged users to import CSV files, but it does not properly validate the file paths, leading to a potential security risk.
Defensive priority
Administrators of WordPress installations using the Import and export users and customers plugin should verify the plugin version and update to 2.4.3 or later if necessary.
Recommended defensive actions
- Verify plugin version and update to 2.4.3 or later
- Restrict file access controls for high-privileged users
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The evidence for this CVE is limited. The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. This issue was reported by Wpscan. Defenders should verify plugin version and file access controls. Additional information may be needed to fully understand the vulnerability's impact.
Official resources
-
CVE-2025-15673 CVE record
CVE.org
-
CVE-2025-15673 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T07:16:37.257Z and has not been modified since then.