Simple User Import Export
Simple User Import Export has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 6.6 out of 10.
The most common weakness is Improper Neutralization Of Formula Elements In A CSV File, behind 1 of the records (100%).
The one issue recorded for Simple User Import Export has a vendor fix available, so running the current release closes it.
All of these findings were reported by Ivan Cese. Simple User Import Export is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-13133Simple User Import Export <= 1.1.7 - Authenticated (Admin+) CSV Injection
Read the full analysisVulnerability Records

Simple User Import Export
Author
vaniivan
Import and export WordPress and WooCommerce users with ease. Supports user meta fields. Compatible with Shopify exports. Major features in Simple User Import Export include: WordPress user import and export WooCommerce customer import and export Shopify export tested Import file preview Save current import/export settings to continue next time Drag & drop support User Meta import and export support Templated import fields (compose an import field from multiple csv fields and custom text) Importing passwords with clear text or hash AJAX import with selectable batch size Responsive UI (mobile friendly)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C