CVE-2025-12894
BaseFortify
Publication date: 2025-11-21
Last updated on: 2025-11-21
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpres | import_wp | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Import WP β Export and Import CSV and XML files to WordPress plugin up to version 2.14.17. It allows unauthenticated attackers to access sensitive information by exploiting the import/export functionality and the lack of .htaccess protection on certain directories (/exportwp and /importwp), enabling extraction of sensitive data stored there.
How can this vulnerability impact me? :
The vulnerability can lead to exposure of sensitive information to unauthorized parties, potentially compromising data confidentiality. Since attackers do not need to authenticate, sensitive export and import data stored in the plugin's directories can be accessed and extracted, which may lead to data leaks.