WordPress Export and Import Users and Customers Plugin Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing authenticated users with Administrator-level access to delete arbitrary log files on the server has been identified in the WordPress Export and Import Users and Customers plugin, versions 2.6.2 and prior. This issue arises from inadequate validation of file paths in the 'admin_log_page' function, which could be exploited to perform unauthorized file deletions.

Impact

Exploitation of this vulnerability allows for limited arbitrary file deletion on the server.

Reproduction

The vulnerability can be reproduced by an authenticated user with Administrator privileges. When the 'admin_log_page' is accessed, the plugin does not properly validate the file paths of log files intended for deletion. This lack of validation can be exploited to delete specific log files from the server.

Remediation

Users are advised to update the WordPress Export and Import Users and Customers plugin to version 2.6.3 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
5.8
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.