PatchSiren

Smackcoders Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Smackcoders Inc. CVE published 2026-10-10

CVE-2026-45440

A high-severity SQL injection vulnerability exists in the WP Ultimate CSV Importer plugin versions up to 9.2. An administrator must have high privileges to exploit this vulnerability, which could allow them to execute arbitrary SQL queries. This could potentially lead to sensitive information disclosure or limited data tampering.