WordPress Plugin Vulnerabilities
Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
Description
The plugin does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
TRAVERSAL
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Centesiman
Submitter
Centesiman
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-24 (about 11 days ago)
Added
2026-07-24 (about 10 days ago)
Last Updated
2026-07-24 (about 10 days ago)