Sensitive Information Exposure in WordPress Plugin by Vendor
CVE-2025-12894
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 November 2025
What is CVE-2025-12894?
The Import WP – Export and Import CSV and XML files to WordPress plugin is susceptible to a vulnerability that allows unauthenticated attackers to access sensitive data. This occurs due to improper protection of files generated during import/export operations, specifically in the directories /exportwp and /importwp. Without adequate .htaccess restrictions, sensitive information can be easily extracted, posing a significant security risk for users relying on this plugin for data management.
Affected Version(s)
Import WP – Export and Import CSV and XML files to WordPress * <= 2.14.17