CVE-2026-16542 - Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar
CVE ID :CVE-2026-16542
Published : Sept. 20, 2026, 6 a.m. | 1 hour, 9 minutes ago
Description :The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 20, 2026, 6 a.m. | 1 hour, 9 minutes ago
Description :The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...