WordPress · Export/Import Users/Customers · CVE-2025-15673
**Name of the Vulnerable Software and Affected Versions**
Import and export users and customers WordPress plugin versions prior to 2.4.3
**Description**
High-privileged users can read arbitrary files on the server because the plugin does not restrict the file path during a CSV import process.
**Recommendations**
Update the plugin to version 2.4.3 or later.