PT-2025-14025 · WordPress · Import Export Suite For Csv/Xml Datafeed

Michael Mazzolini

·

Published

2025-04-01

·

Updated

2025-04-02

·

CVE-2025-2007

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Import Export Suite for CSV and XML Datafeed plugin for WordPress versions up to, and including, 7.19
Description The issue is related to insufficient file path validation in the deleteImage() function, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary files on the server. This can lead to remote code execution if critical files, such as wp-config.php, are deleted.
Recommendations For versions up to, and including, 7.19, consider disabling the deleteImage() function until a patch is available to prevent arbitrary file deletion. Restrict access to sensitive files on the server to minimize the risk of exploitation.

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2025-2007

Affected Products

Import Export Suite For Csv/Xml Datafeed