---
id: CVE-2025-12879
title: >-
  The User Generator and Importer plugin for WordPress is vulnerable to
  Cross-Site Request Forgery in versions up to and including 1.2.2
summary: >-
  The User Generator and Importer plugin for WordPress is vulnerable to
  Cross-Site Request Forgery in versions up to and including 1.2.2. This is due
  to missing nonce validation in the "Import Using CSV File" function. This
  makes it possib…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-352
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12879'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/user-importer-and-generator/tags/1.2.2/user-generator.php#L145
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/82699a17-ea45-4493-98c4-07f62ca0b1f9?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00184
epssPercentile: 0.07127
ingestedAt: '2026-09-25T23:21:16.890Z'
---

## Overview

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce validation in the "Import Using CSV File" function. This makes it possible for unauthenticated attackers to elevate user privileges by creating arbitrary accounts with administrator privileges via a forged request, provided they can trick a site administrator into performing an action such as clicking on a link.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
