PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15673 WordPress.org CVE debrief

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. This issue was reported by Wpscan. The vulnerability could allow an attacker to access sensitive information on the server. Defenders should verify plugin version and file access controls. Additional information may be needed to fully understand the vulnerability's impact. The evidence for this CVE is limited, and security teams should review the affected scope and severity of this vulnerability.

Vendor
WordPress.org
Product
Import and export users and customers
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-03
Advisory published
2026-08-03
Advisory updated
2026-08-03

Who should care

WordPress administrators using the Import and export users and customers plugin should be aware of this vulnerability and take necessary actions to protect their installations. This includes verifying the plugin version, restricting file access controls, and monitoring for potential security breaches. Additionally, security teams and vulnerability management teams should review the affected scope and severity of this vulnerability.

Technical summary

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict file paths during CSV imports, allowing high-privileged users to read arbitrary server files. This vulnerability could allow an attacker to access sensitive information on the server. The plugin's functionality allows high-privileged users to import CSV files, but it does not properly validate the file paths, leading to a potential security risk.

Defensive priority

Administrators of WordPress installations using the Import and export users and customers plugin should verify the plugin version and update to 2.4.3 or later if necessary.

Recommended defensive actions

  • Verify plugin version and update to 2.4.3 or later
  • Restrict file access controls for high-privileged users
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The evidence for this CVE is limited. The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. This issue was reported by Wpscan. Defenders should verify plugin version and file access controls. Additional information may be needed to fully understand the vulnerability's impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T07:16:37.257Z and has not been modified since then.