
CVE-2025-15673 The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-… https://www.cve.org/CVERecord?id=CVE-2025-15673
Post summary
The Import and Export Users and Customers WordPress plugin (v < 2.4.3) lacks proper path restrictions during CSV import, enabling a path traversal vulnerability.

