The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration
Metrics
Affected Vendors & Products
References
History
Tue, 18 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Tue, 18 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration | |
| Title | Simple User Import Export <= 1.1.7 - Authenticated (Admin+) CSV Injection | |
| Weaknesses | CWE-1236 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-18T09:27:37.077Z
Updated: 2025-11-18T21:32:02.192Z
Reserved: 2025-11-13T18:10:42.350Z
Link: CVE-2025-13133
Updated: 2025-11-18T21:23:29.954Z
Status : Awaiting Analysis
Published: 2025-11-18T10:15:49.420
Modified: 2025-11-18T14:06:29.817
Link: CVE-2025-13133
No data.