CSV Injection Vulnerability in Simple User Import Export Plugin for WordPress
CVE-2025-13133
What is CVE-2025-13133?
The Simple User Import Export Plugin for WordPress contains a vulnerability that allows authenticated attackers with Administrator-level access to inject malicious code into exported CSV files through the 'Import/export users' function. When these CSV files are downloaded and opened on a local system with susceptible configurations, this could lead to unintended code execution, posing risks to the integrity of user data. It is imperative for users to ensure they are using the most recent and secure versions of this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Simple User Import Export * <= 1.1.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved