Impact
The Import and export users and customers WordPress plugin before version 2.4.5 does not validate the user‑provided URL that is requested server‑side during a CSV import. This omission allows any administrator or other high‑privileged user to issue Server‑Side Request Forgery attacks, potentially causing the site to reach internal network addresses, access protected APIs, or retrieve sensitive data. The flaw is a classic server‑side request forger, exposing the web server to uncontrolled outbound network traffic.
Affected Systems
The vulnerability affects the Import and export users and customers WordPress plugin version earlier than 2.4.5. Any WordPress installation using this plugin and granting admin or other high‑privileged users the ability to perform CSV imports is susceptible. The issue is not tied to specific server configurations beyond the presence of the plugin.
Risk and Exploitability
The CVSS score is not provided and the EPSS score is unavailable, but the lack of input validation coupled with privileged access yields a high potential risk. The attack vector is a Server‑Side Request Forgery performed by a high‑privileged WordPress user during a CSV import. Because the flaw is a server‑side control failure, exploitation does not require additional network exposure and can be executed from any authenticated admin account. While the vulnerability is not listed in CISA KEV, its impact warrants immediate remediation.
OpenCVE Enrichment