CVE-2025-2007: Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Deletion
The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteImage() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2007?
CVE-2025-2007 is rated as a critical vulnerability due to its potential for arbitrary file deletion.
How do I fix CVE-2025-2007?
To fix CVE-2025-2007, update the Import Export Suite for CSV and XML Datafeed plugin to version 7.20 or later.
Who is affected by CVE-2025-2007?
CVE-2025-2007 affects all installations of the Import Export Suite for CSV and XML Datafeed plugin up to and including version 7.19.
What types of attacks can exploit CVE-2025-2007?
CVE-2025-2007 can be exploited by authenticated attackers to delete arbitrary files on the server.
Is my website safe if I have not installed the affected version of the plugin for CVE-2025-2007?
If you do not have the Import Export Suite for CSV and XML Datafeed plugin version 7.19 or earlier installed, your website is not affected by CVE-2025-2007.