CVE-2025-12137

Publication date

2025-11-01 06:40:40

Family

Wordfence

State

PUBLISHED

Description

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugins REST API endpoint accepting arbitrary absolute file paths without proper validation in the attach_file() function when handling file_local actions. This makes it possible for authenticated attackers, with administrator-level access and above, to read arbitrary files on the servers filesystem, including sensitive configuration files and system files via the local_url parameter.