CVE-2025-1972
CVSS 3.1 Score 2.7 of 10 (low)
Details
Published Mar 22, 2025
CWE ID 73
Summary
CVE-2025-1972 is a vulnerability affecting the Export and Import Users and Customers plugin for WordPress. This issue stems from insufficient file path validation within the admin_log_page() function, which is present in all versions up to 2.6.2. Authenticated attackers, including those with Administrator-level access, can take advantage of this flaw to delete arbitrary log files on the server. This vulnerability poses a significant risk as it enables unintended file deletion, potentially impacting the system's stability and data integrity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.