WordPress Simple User Import Export Plugin CSV Injection Vulnerability

Vulnerability

A CSV injection vulnerability has been identified in the Simple User Import Export plugin for WordPress, affecting all versions through 1.1.7. The vulnerability arises in the 'Import/export users' function, where authenticated attackers with Administrator-level access can inject untrusted data into exported CSV files. This injected data may be executed as code when the CSV files are downloaded and opened on a local system with a vulnerable configuration.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on a user's local system, triggered by opening the manipulated CSV file.

Remediation

No patch is currently available for this vulnerability. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Nov 18, 2025, 10:20 AM
Updated: Nov 18, 2025, 2:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
0.0
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.