Segurium Research Advisories import-users-from-csv-with-meta

Import and export users and customers 2.4.13 and earlier: Server-side request forgery

medium Server-side request forgery

A remote server could redirect a CSV import in 2.4.13 to a cloud metadata endpoint or a private service, and the plugin followed that redirect without checking the new host. Version 2.4.14 replaces download_url() with a checked fetch.

Plugin
Import and export users and customers import-users-from-csv-with-meta
Affected versions
2.4.13 and earlier
Fixed in
2.4.14
Class
Server-side request forgery
Severity
medium Segurium Research assessment. No CVSS score published yet.
CVE
None assigned at the time of writing
Installs
70,000 active
Patch released
Sources
Read the teardown What the release changed, how the bug worked, and what to check on a site that ran the affected version.

Segurium Research writes these up from public source after the fix has shipped. We do not scan or probe third-party sites, and no teardown here carries a working exploit. Segurium itself is a WordPress malware scanner on the official directory at wordpress.org/plugins/segurium/.