CVE-2025-1973: Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the downloadfile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1973?
CVE-2025-1973 is considered a high severity vulnerability due to the potential for authenticated attackers to exploit path traversal to access sensitive files.
How do I fix CVE-2025-1973?
To fix CVE-2025-1973, update the Export and Import Users and Customers plugin to version 2.6.3 or later.
Who is affected by CVE-2025-1973?
CVE-2025-1973 affects users of the Export and Import Users and Customers plugin for WordPress versions up to and including 2.6.2.
What function is exploited in CVE-2025-1973?
The vulnerability in CVE-2025-1973 is exploited through the download_file() function.
What type of access is required to exploit CVE-2025-1973?
Exploiting CVE-2025-1973 requires authenticated access with Administrator-level permissions.