Impact
The WordPress plugin Import and export users and customers does not limit the file path it opens when processing a CSV import. An administrator with sufficient privileges can provide a path that points to any server file, causing the plugin to read and display that file’s contents. This flaw enables unauthorized disclosure of any file reachable by the web server user and can expose sensitive data or configuration information.
Affected Systems
Any installation of the Import and export users and customers plugin with a version earlier than 2.4.3 is affected. The vulnerability is present in all builds of that plugin before the 2.4.3 release.
Risk and Exploitability
The flaw is exploitable only by users who have administrative rights within WordPress, so the attack vector is the plugin’s import interface. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, but because it grants arbitrary file read to high‑privileged users, the risk to confidentiality is high. The CVSS score of 4.9 indicates moderate severity, and the potential for confidential data disclosure indicates a significant risk.
OpenCVE Enrichment