WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Export and Import Users and Customers

Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.

8Reported vulnerabilities
7.6Highest CVSS score
2.7.5Latest version
60,000+Active installs

What to do now

Update Export and Import Users and Customers to 2.6.3 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 18, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-1970 High 7.6 0.4% Before 2.6.3 2.6.3 March 22, 2025
CVE-2023-6558 High 7.2 1.4% 2.4.8 and earlier 2.4.9 January 11, 2024
CVE-2023-3459 High 7.2 0.9% 2.4.1 and earlier 2.4.2 July 18, 2023
CVE-2025-1971 High 7.2 0.7% Before 2.6.3 2.6.3 March 22, 2025
CVE-2025-1972 Medium 6.5 0.4% Before 2.6.3 2.6.3 March 22, 2025
CVE-2024-32835 Medium 5.4 0.4% 2.5.3 and earlier 2.5.4 April 24, 2024
CVE-2025-1973 Medium 4.9 0.7% Before 2.6.3 2.6.3 March 22, 2025
CVE-2024-30492 Medium 4.3 0.5% 2.5.2 and earlier
0 to 2.5.2 (inclusive)
2.5.3 March 29, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.