What is CVE-2025-15673?
CVE-2025-15673 is a Path Traversal vulnerability in the 'Import and export users and customers' WordPress plugin before version 2.4.3. It allows high-privileged users to read arbitrary files on the server during a CSV import. Update the plugin to the latest patched version immediately.
Azərbaycanca: CVE-2025-15673: WordPress üçün 'Import and export users and customers' plagininin 2.4.3-dən əvvəlki versiyalarında kəşf edilmiş Path Traversal zəifliyidir. Yüksək səlahiyyətli istifadəçilər CSV idxalı zamanı serverdəki ixtiyari faylları oxuya bilərlər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which WordPress plugin is affected by CVE-2025-15673?
This vulnerability affects the 'Import and export users and customers' plugin in versions prior to 2.4.3.
What can happen if CVE-2025-15673 is exploited?
High-privileged users can read arbitrary files on the server during a CSV import.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.