The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file. This vulnerability allows unauthenticated attackers to access sensitive informati [truncated]
ReviewWP Ultimate CSV ImporterCVE published 2026-10-03
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate file types in uploaded archives or sanitize their content before storing them in a publicly served location. This allows high privilege users, such as administrators, to achieve Stored Cross-Site Scripting. On Multisite installations, site Administrators do not hold the unfiltered_html capability, enabling them to run scri [truncated]