← WordPress Vulnerabilities
WordPress security by component

Import and export users and customers

Import and export users and customers is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 9.1.

Plugin slug: import-and-export-users-and-customers

CVE-2026-16534: CSV imports permit administrator creation and account takeover

Import and export users and customers before 2.4.2 does not enforce WordPress role-assignment or per-user edit restrictions while importing CSV records. A user holding the user-creation capability can assign Administrator to a new account or overwrite an existing Administrator's email address or password, enabling privilege escalation and account takeover. The CNA record does not disclose the import route, CSV columns or import functions.

PublishedAug 03, 2026
Known safe version2.4.2
Published vulnerabilities for import-and-export-users-and-customers
Safe version
Aug 03, 2026 CVE-2026-16534
CSV imports permit administrator creation and account takeover
Import and export users and customers before 2.4.2 does not enforce WordPress role-assignment or per-user edit restrictions while importing CSV records. A user holding the user-creation capability can assign Administrator to a new account or overwrite an existing Administrator's email address or password, enabling privilege escalation and account takeover. The CNA record does not disclose the import route, CSV columns or import functions.
2.4.2
CVE9.1
NVDPending
Aug 03, 2026 CVE-2025-15673
CSV import previews permit arbitrary server-file reads
Import and export users and customers before 2.4.3 does not restrict the filesystem path of a file read and displayed during CSV import. A high-privilege user with access to the import workflow can supply an arbitrary server path and disclose readable files. The CNA record does not disclose the route, path parameter, read function, output context or minimum capability.
2.4.3
CVE4.9
NVDPending
May 15, 2024 CVE-2024-4734
Import and export users and customers: Cross-site scripting
Import and export users and customers is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.4
NVDPending
May 15, 2024 CVE-2024-4656
Import and export users and customers: Cross-site scripting
Import and export users and customers is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.4
NVDPending
Jan 11, 2024 CVE-2023-6624
Import and export users and customers: Cross-site scripting
Import and export users and customers is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.9
NVD5.4
Jan 11, 2024 CVE-2023-6583
Import and export users and customers: Filesystem traversal
Import and export users and customers is affected by filesystem traversal. Exploitation requires an authenticated administrator account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.6
NVD7.2
Nov 07, 2022 CVE-2022-3558
Import and export users and customers: A security weakness
Import and export users and customers is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.0
NVD8.0
May 02, 2022 CVE-2022-1255
Import and export users and customers: Cross-site scripting
Import and export users and customers is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVEPending
NVD4.8