Impact
Before version 2.4.5 the Import and export users and customers WordPress plugin accepts a URL input and performs a server‑side request during a CSV import without validating it. This gap permits any administrator or other high‑privileged user to instruct the web server to fetch that URL, creating a Server‑Side Request Forgery flaw.
Affected Systems
The vulnerability applies to the Import and export users and customers WordPress plugin versions earlier than 2.4.5. Any WordPress site that has this plugin installed and allows admins or other privileged accounts to run the CSV import feature is at risk. No special server configuration is required beyond the presence of the plugin.
Risk and Exploitability
The CVSS score of 4.1 signifies low severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. An attacker needs only a high‑privileged WordPress account to trigger the CSV import; no additional external exposure or privileges are required. The SSRF flaw enables the server to reach arbitrary destinations it can access, potentially exposing the site to unwanted outbound traffic.
OpenCVE Enrichment