PatchSiren

WP Ultimate CSV Importer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review WP Ultimate CSV Importer CVE published 2026-10-03

CVE-2026-80518

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file. This vulnerability allows unauthenticated attackers to access sensitive informati [truncated]

Review WP Ultimate CSV Importer CVE published 2026-10-03

CVE-2026-80517

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate file types in uploaded archives or sanitize their content before storing them in a publicly served location. This allows high privilege users, such as administrators, to achieve Stored Cross-Site Scripting. On Multisite installations, site Administrators do not hold the unfiltered_html capability, enabling them to run scri [truncated]