CyberRota Analysis
AI-GeneratedThe Import and Export Users and Customers plugin for WordPress versions prior to 2.4.3 is vulnerable due to inadequate path restrictions during CSV imports, enabling high-privileged users to access arbitrary files on the server. This could lead to unauthorized disclosure of sensitive information, potentially compromising the integrity and confidentiality of the server. WordPress administrators and security teams should prioritize updating this plugin to mitigate the risk of exploitation.
Original NVD Description
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.