HIGH
Smackcoders Inc.
CVE published 2026-10-10
CVE-2026-45440
A high-severity SQL injection vulnerability exists in the WP Ultimate CSV Importer plugin versions up to 9.2. An administrator must have high privileges to exploit this vulnerability, which could allow them to execute arbitrary SQL queries. This could potentially lead to sensitive information disclosure or limited data tampering.