CVE-2025-1973 | webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress download_file path traversal
A vulnerability classified as critical was found in webtoffee Export and Import Users and Customers Plugin up to 2.6.2 on WordPress. This vulnerability affects the function download_file. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-1973. The attack can be initiated remotely. There is no exploit available.