CVE-2025-2008: Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Upload
The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the importsinglepostascsv() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2008?
CVE-2025-2008 has a high severity rating due to the potential for arbitrary file uploads by authenticated attackers.
How do I fix CVE-2025-2008?
To fix CVE-2025-2008, update the WordPress Import Export Suite for CSV and XML Datafeed plugin to the latest version beyond 7.19.
Who is affected by CVE-2025-2008?
CVE-2025-2008 affects all versions of the WordPress Import Export Suite for CSV and XML Datafeed plugin up to and including version 7.19.
What type of attack can CVE-2025-2008 enable?
CVE-2025-2008 can enable authenticated attackers to upload arbitrary files to the server.
Is CVE-2025-2008 a common vulnerability?
CVE-2025-2008 is a notable vulnerability due to its exploitation potential within WordPress environments, particularly for users of the affected plugin.