CVE-2025-1311
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 22, 2025
CWE ID 89
Summary
CVE-2025-1970 is a Server-Side Request Forgery (SSRF) vulnerability affecting the Export and Import Users and Customers plugin for WordPress. This issue, present in versions up to and including 2.6.2, allows authenticated attackers with Administrator-level access or higher to issue web requests from the WordPress application to arbitrary locations. The vulnerability is rooted in the plugin's validate_file() function and can be exploited to query and modify information from internal services, posing a significant risk to sensitive data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.