Impact
An administrator authenticated user can upload any file type through the Really Simple CSV Importer plugin up to version 1.3 because the plugin does not validate the uploaded file’s MIME type or extension. This flaw is a classic arbitrary file upload vulnerability (CWE‑434) and could allow an attacker to upload malicious files to the WordPress installation, potentially leading to further exploitation.
Affected Systems
The plugin "Really Simple CSV Importer" produced by Web in all releases up to and including version 1.3. No specific patch version is listed except the recommendation that 1.3.1 or newer contains the fix.
Risk and Exploitability
The CVSS score of 9.1 indicates a severe risk, and while the EPSS score of < 1% indicates a very low probability of exploitation, the vulnerability is not listed in CISA KEV. Because the flaw requires an authenticated administrator, an attacker who can obtain or already possesses admin rights could use the plugin to upload arbitrary files. These files could potentially be exploited to compromise the WordPress site, but no specific exploitation method is detailed in the CVE report.
OpenCVE Enrichment