Impact
The Import WP WordPress plugin prior to version 2.14.23 contains an export-file download handler that performs no authorization check. An unauthenticated attacker who knows or can guess the low‑entropy, time‑based download key can download an export file that has already been produced by an administrator. Those export files may include personal user data such as email addresses, login names, and role information, representing a direct compromise of confidentiality.
Affected Systems
This weakness affects any WordPress installation that uses the Import WP plugin before the 2.14.23 release. The affected versions are all releases with a version number lower than 2.14.23. No specific operating system or server platform is required; the vulnerability is triggered by web requests to the plugin’s export endpoint.
Risk and Exploitability
Because the attack does not require authentication, the potential for exploitation exists for anyone who can access the site’s URL space. The only prerequisites are that an export file has been generated by a user with administrative privileges and that the attacker can obtain or guess the short, time‑based download key. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, so the overall risk is evaluated qualitatively: the impact on confidentiality is high, even though the probability of exploitation depends on the attacker’s ability to discover the key.
OpenCVE Enrichment