CVE-2026-16542: CWE-918 Server-Side Request Forgery (SSRF) in Import and export users and customers
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
AI Analysis
Technical Summary
The Import and export users and customers WordPress plugin versions prior to 2.4.5 do not validate user-supplied URLs during CSV import operations. This lack of validation enables high-privileged users to perform SSRF attacks by causing the server to make arbitrary HTTP requests to internal or external resources. The vulnerability is identified as CWE-918 and is tracked as CVE-2026-16542.
Potential Impact
High-privileged users can exploit this vulnerability to make the server perform unintended HTTP requests, potentially accessing internal services or resources not normally accessible. The exact impact depends on the server environment and network configuration but could lead to information disclosure or further internal network attacks.
Mitigation Recommendations
Upgrade the Import and export users and customers plugin to version 2.4.5 or later, where this vulnerability is fixed. No other mitigation guidance is provided. Patch status is confirmed by the version boundary indicating the fix in 2.4.5.
CVE-2026-16542: CWE-918 Server-Side Request Forgery (SSRF) in Import and export users and customers
Description
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
CVSS v3.1
Score 4.1medium
Affected software
Import and export users and customers
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Import and export users and customers WordPress plugin versions prior to 2.4.5 do not validate user-supplied URLs during CSV import operations. This lack of validation enables high-privileged users to perform SSRF attacks by causing the server to make arbitrary HTTP requests to internal or external resources. The vulnerability is identified as CWE-918 and is tracked as CVE-2026-16542.
Potential Impact
High-privileged users can exploit this vulnerability to make the server perform unintended HTTP requests, potentially accessing internal services or resources not normally accessible. The exact impact depends on the server environment and network configuration but could lead to information disclosure or further internal network attacks.
Mitigation Recommendations
Upgrade the Import and export users and customers plugin to version 2.4.5 or later, where this vulnerability is fixed. No other mitigation guidance is provided. Patch status is confirmed by the version boundary indicating the fix in 2.4.5.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-22T09:43:42.454Z
- State
- PUBLISHED
Threat ID: 6aaf7de855bf5e2cf5adcf92
Added to database: 09/20/2026, 06:32:08 UTC
Last enriched: 09/20/2026, 06:47:45 UTC
Last updated: 09/21/2026, 01:42:24 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.