WP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information Exposure
CVE-2025-12732
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 November 2025
What is CVE-2025-12732?
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level access or higher, to extract sensitive information including OpenAI API keys configured through the plugin's admin interface.
Affected Version(s)
WP Import – Ultimate CSV XML Importer for WordPress * <= 7.33