Vulnerability Description
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary log files on the server.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webtoffee | Import Export Wordpress Users | < 2.6.3 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/users-customers-import-export-for-wp-Product
- https://plugins.trac.wordpress.org/changeset/3259688/Patch
- https://wordpress.org/plugins/users-customers-import-export-for-wp-woocommerce/#Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2d443c70-6537-4c6d-a28Third Party Advisory
FAQ
What is CVE-2025-1972?
CVE-2025-1972 is a vulnerability with a CVSS score of 2.7 (LOW). The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to,...
How severe is CVE-2025-1972?
CVE-2025-1972 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1972?
Check the references section above for vendor advisories and patch information. Affected products include: Webtoffee Import Export Wordpress Users.