Junglewise Threat Intelligence

CVE-2026-16542: Import and export users and customers Server-Side Request Forgery

CVE-2026-16542 · Severity: medium · CVSS 4.1 · Published 2026-09-20

Executive brief

A WordPress plugin used to import and export user data fails to validate URLs provided during CSV import operations. High-privileged administrators can exploit this to make the server send requests to internal systems, potentially accessing sensitive internal services or data that should not be exposed.

Technical details

The plugin does not validate user-supplied URLs before fetching them server-side during CSV import, enabling Server-Side Request Forgery (SSRF) attacks. The vulnerability affects the bp_avatar parameter and requires administrator-level privileges to exploit. The vulnerability is patched in version 2.4.5.

Affected products

  • Import and export users and customers before 2.4.5

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Fixed in version 2.4.5

References