Vulnerability Description
The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aleapp | Csv Mass Importer | <= 1.2 |
References
- https://wpscan.com/vulnerability/e525ece5-6e03-4aee-bf5b-6ae0b961f027/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/e525ece5-6e03-4aee-bf5b-6ae0b961f027/ExploitThird Party Advisory
FAQ
What is CVE-2025-4190?
CVE-2025-4190 is a vulnerability with a CVSS score of 7.2 (HIGH). The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should ...
How severe is CVE-2025-4190?
CVE-2025-4190 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-4190?
Check the references section above for vendor advisories and patch information. Affected products include: Aleapp Csv Mass Importer.