Description
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
Published: 2026-09-20
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

Before version 2.4.5 the Import and export users and customers WordPress plugin accepts a URL input and performs a server‑side request during a CSV import without validating it. This gap permits any administrator or other high‑privileged user to instruct the web server to fetch that URL, creating a Server‑Side Request Forgery flaw.

Affected Systems

The vulnerability applies to the Import and export users and customers WordPress plugin versions earlier than 2.4.5. Any WordPress site that has this plugin installed and allows admins or other privileged accounts to run the CSV import feature is at risk. No special server configuration is required beyond the presence of the plugin.

Risk and Exploitability

The CVSS score of 4.1 signifies low severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. An attacker needs only a high‑privileged WordPress account to trigger the CSV import; no additional external exposure or privileges are required. The SSRF flaw enables the server to reach arbitrary destinations it can access, potentially exposing the site to unwanted outbound traffic.

Generated by OpenCVE AI on September 20, 2026 at 16:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Import and export users and customers WordPress plugin to version 2.4.5 or newer to eliminate the SSRF flaw.
  • Restrict the CSV import capability to trusted administrator accounts and remove it from lower‑privilege roles.
  • Configure the web server or host firewall to block outbound requests to unintended or internal addresses, limiting the reach of any remaining SSRF attempts.
  • Monitor web server logs for unexpected outbound requests that are generated during the CSV import process.

Generated by OpenCVE AI on September 20, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions import And Export Users And Customers
Vendors & Products Wordpress-extensions
Wordpress-extensions import And Export Users And Customers

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
Title Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar
References

Subscriptions

Wordpress-extensions Import And Export Users And Customers
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:45:24.876Z

Reserved: 2026-07-22T09:43:42.454Z

Link: CVE-2026-16542

cve-icon Vulnrichment

Updated: 2026-09-20T13:45:11.552Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:49.467

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-16542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:00Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)