WordPress Plugin Vulnerabilities

Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read

Description

The plugin does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.

Proof of Concept

Affects Plugins

References

Classification

Type
TRAVERSAL
OWASP top 10
CWE

Miscellaneous

Original Researcher
Centesiman
Submitter
Centesiman
Verified
Yes

Timeline

Publicly Published
2026-07-24 (about 11 days ago)
Added
2026-07-24 (about 10 days ago)
Last Updated
2026-07-24 (about 10 days ago)

Other