CSV Injection Vulnerability in Simple User Import Export Plugin for WordPress
CVE-2025-13133
6.6MEDIUM
What is CVE-2025-13133?
The Simple User Import Export Plugin for WordPress contains a vulnerability that allows authenticated attackers with Administrator-level access to inject malicious code into exported CSV files through the 'Import/export users' function. When these CSV files are downloaded and opened on a local system with susceptible configurations, this could lead to unintended code execution, posing risks to the integrity of user data. It is imperative for users to ensure they are using the most recent and secure versions of this plugin.
Affected Version(s)
Simple User Import Export * <= 1.1.7