Description
Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
Published: 2026-10-10
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Remote Database Manipulation and Potential Data Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an SQL injection flaw that can be exercised by any site administrator. It allows the injection of arbitrary SQL statements, enabling an attacker to read, alter, or delete data across the WordPress database. The gain of privileges leads to full compromise of site integrity and confidentiality.

Affected Systems

WP Ultimate CSV Importer plugin versions 9.2 and earlier, distributed by Smackcoders Inc., are affected. The plugin must be installed on WordPress sites.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the KEV status shows it is not listed as a known exploited vulnerability. The attack requires administrator access to the WordPress backend and exposure of plugin endpoints, making it likely that only sites with exposed admin interfaces or known credentials are at risk.

Generated by OpenCVE AI on October 10, 2026 at 20:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Ultimate CSV Importer to the latest version that addresses the SQL Injection bug.
  • If an immediate upgrade is not possible, temporarily disable the plugin or restrict access to its administrative pages to trusted IP addresses.
  • Audit the database for any suspicious changes and ensure that database credentials are kept secure and not exposed.

Generated by OpenCVE AI on October 10, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
Title WordPress WP Ultimate CSV Importer plugin <= 9.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:22.690Z

Reserved: 2026-05-12T13:08:41.670Z

Link: CVE-2026-45440

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:37.740

Modified: 2026-10-10T20:16:37.740

Link: CVE-2026-45440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T20:45:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')