PatchSiren cyber security CVE debrief
CVE-2026-80517 WP Ultimate CSV Importer CVE debrief
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate file types in uploaded archives or sanitize their content before storing them in a publicly served location. This allows high privilege users, such as administrators, to achieve Stored Cross-Site Scripting. On Multisite installations, site Administrators do not hold the unfiltered_html capability, enabling them to run scripts in the session of users who view the file, including Network Super Admins.
- Vendor
- WP Ultimate CSV Importer
- Product
- WP Ultimate CSV Importer
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for WordPress installations using the WP Ultimate CSV Importer plugin should assess exposure and prioritize updates and monitoring. This includes operators managing WordPress environments, platform administrators overseeing plugin deployments, vulnerability management teams evaluating potential impacts, and security teams responsible for monitoring and incident response.
Why it matters
CVE-2026-80517 allows Stored Cross-Site Scripting in the WP Ultimate CSV Importer plugin. High privilege users can upload malicious files, potentially executing scripts in the sessions of users who view these files. Defenders should verify plugin versions, restrict upload capabilities, and monitor user activity.
- Potential for Stored Cross-Site Scripting attacks on users viewing malicious files.
- Exposure of high privilege users, such as administrators, to script execution.
- Possible exploitation through file uploads by high privilege users.
- Verification of plugin version and user access controls required.
Technical summary
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate file types in uploaded archives or sanitize their content before storing them in a publicly served location. This allows high privilege users, such as administrators, to achieve Stored Cross-Site Scripting. On Multisite installations, site Administrators do not hold the unfiltered_html capability, enabling them to run scripts in the session of users who view the file, including Network Super Admins.
Defensive priority
Defenders should prioritize verifying and updating the WP Ultimate CSV Importer plugin to version 9.2 or later, restricting upload capabilities to trusted users, and monitoring for suspicious file uploads and user activity.
Recommended defensive actions
- Verify and update the WP Ultimate CSV Importer plugin to version 9.2 or later.
- Restrict upload capabilities to trusted users.
- Monitor for suspicious file uploads and user activity.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in the WP Ultimate CSV Importer plugin. The vulnerability allows for Stored Cross-Site Scripting due to improper validation and sanitization of uploaded files.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80517 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80517
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80517 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80517
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/2ac66402-2a79-42dd-9056-12c819112f07/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.