CVE-2025-1972

Source
https://cve.org/CVERecord?id=CVE-2025-1972
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1972.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-1972
Published
2025-03-22T12:15:26.453Z
Modified
2026-03-14T01:48:36.108010Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the adminlogpage() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary log files on the server.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1972.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "2.6.3"
            }
        ]
    }
]