Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7279 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information. |
Wed, 09 Jul 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webtoffee
Webtoffee import Export Wordpress Users |
|
| CPEs | cpe:2.3:a:webtoffee:import_export_wordpress_users:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Webtoffee
Webtoffee import Export Wordpress Users |
Mon, 24 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 22 Mar 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information. | |
| Title | Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:36:41.274Z
Reserved: 2025-03-04T21:06:31.898Z
Link: CVE-2025-1973
Updated: 2025-03-24T17:36:18.048Z
Status : Analyzed
Published: 2025-03-22T12:15:26.653
Modified: 2025-07-09T17:43:34.383
Link: CVE-2025-1973
No data.
OpenCVE Enrichment
Updated: 2026-04-22T17:45:22Z
EUVD