Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smackcoders
Smackcoders wp Import – Ultimate Csv Xml Importer For Wordpress Wordpress Wordpress wordpress |
|
| Vendors & Products |
Smackcoders
Smackcoders wp Import – Ultimate Csv Xml Importer For Wordpress Wordpress Wordpress wordpress |
Wed, 18 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.37. This is due to insufficient escaping on the `file_name` parameter which is stored in the database during file upload and later used in raw SQL queries without proper sanitization. This makes it possible for authenticated attackers with Subscriber-level access or higher to append additional SQL queries into already existing queries via a malicious filename, which can be used to extract sensitive information from the database. The vulnerability can only be exploited when the 'Single Import/Export' option is enabled, and the server is running a PHP version < 8.0. | |
| Title | WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-18T20:24:06.821Z
Reserved: 2026-01-21T23:41:23.912Z
Link: CVE-2026-1317
Updated: 2026-02-18T20:24:03.645Z
Status : Awaiting Analysis
Published: 2026-02-18T13:16:20.167
Modified: 2026-02-18T17:51:53.510
Link: CVE-2026-1317
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:20:15Z