What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2.
Explanation of Vulnerability in Simple Terms
02Summary
The Import Export WordPress Users plugin through version 2.5.2 contains a path traversal vulnerability in file handling. An authenticated user with low privileges can read arbitrary files from the server by manipulating file paths during import or export operations. This allows access to sensitive configuration files and other non-public data stored on the web server.
What an attacker can do
03Attacker Capabilities
Read arbitrary files from the server, including configuration files and other sensitive data.
Potential impact on your site
04Site Impact
Sensitive files like wp-config.php, database backups, or private user data could be exposed to authenticated users.
Conditions required to exploit
05Prerequisites
Attacker must have a WordPress user account with at least low-level privileges (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
March 29, 2024
CVE published
April 28, 2026
Record updated