CVE-2025-1972

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Mar 22, 2025
CWE ID 73

Summary

CVE-2025-1972 is a vulnerability affecting the Export and Import Users and Customers plugin for WordPress. This issue stems from insufficient file path validation within the admin_log_page() function, which is present in all versions up to 2.6.2. Authenticated attackers, including those with Administrator-level access, can take advantage of this flaw to delete arbitrary log files on the server. This vulnerability poses a significant risk as it enables unintended file deletion, potentially impacting the system's stability and data integrity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share