CSV Injection Vulnerability in Simple User Import Export Plugin for WordPress
CVE-2025-13133

6.6MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 November 2025

What is CVE-2025-13133?

The Simple User Import Export Plugin for WordPress contains a vulnerability that allows authenticated attackers with Administrator-level access to inject malicious code into exported CSV files through the 'Import/export users' function. When these CSV files are downloaded and opened on a local system with susceptible configurations, this could lead to unintended code execution, posing risks to the integrity of user data. It is imperative for users to ensure they are using the most recent and secure versions of this plugin.

Affected Version(s)

Simple User Import Export * <= 1.1.7

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Cese
.
CVE-2025-13133 : CSV Injection Vulnerability in Simple User Import Export Plugin for WordPress