PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80517 WP Ultimate CSV Importer CVE debrief

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate file types in uploaded archives or sanitize their content before storing them in a publicly served location. This allows high privilege users, such as administrators, to achieve Stored Cross-Site Scripting. On Multisite installations, site Administrators do not hold the unfiltered_html capability, enabling them to run scripts in the session of users who view the file, including Network Super Admins.

Vendor
WP Ultimate CSV Importer
Product
WP Ultimate CSV Importer
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress installations using the WP Ultimate CSV Importer plugin should assess exposure and prioritize updates and monitoring. This includes operators managing WordPress environments, platform administrators overseeing plugin deployments, vulnerability management teams evaluating potential impacts, and security teams responsible for monitoring and incident response.

Why it matters

CVE-2026-80517 allows Stored Cross-Site Scripting in the WP Ultimate CSV Importer plugin. High privilege users can upload malicious files, potentially executing scripts in the sessions of users who view these files. Defenders should verify plugin versions, restrict upload capabilities, and monitor user activity.

  • Potential for Stored Cross-Site Scripting attacks on users viewing malicious files.
  • Exposure of high privilege users, such as administrators, to script execution.
  • Possible exploitation through file uploads by high privilege users.
  • Verification of plugin version and user access controls required.

Technical summary

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate file types in uploaded archives or sanitize their content before storing them in a publicly served location. This allows high privilege users, such as administrators, to achieve Stored Cross-Site Scripting. On Multisite installations, site Administrators do not hold the unfiltered_html capability, enabling them to run scripts in the session of users who view the file, including Network Super Admins.

Defensive priority

Defenders should prioritize verifying and updating the WP Ultimate CSV Importer plugin to version 9.2 or later, restricting upload capabilities to trusted users, and monitoring for suspicious file uploads and user activity.

Recommended defensive actions

  • Verify and update the WP Ultimate CSV Importer plugin to version 9.2 or later.
  • Restrict upload capabilities to trusted users.
  • Monitor for suspicious file uploads and user activity.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in the WP Ultimate CSV Importer plugin. The vulnerability allows for Stored Cross-Site Scripting due to improper validation and sanitization of uploaded files.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80517 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80517

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80517 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80517

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.