Impact
The WP Ultimate CSV Importer plugin fails to sanitize and escape data imported through its AIOSEO import fields before constructing an SQL query. This omission enables an attacker with administrative privileges to inject arbitrary SQL commands that are executed against the database. As a result, the attacker can read, modify, or delete data, potentially compromising the confidentiality, integrity, or availability of the WordPress site.
Affected Systems
WordPress installations running the WP Ultimate CSV Importer plugin with a version less than 9.0 are affected. Any site using the default import functionality of this plugin prior to the 9.0 release is vulnerable, regardless of the WordPress core version.
Risk and Exploitability
Because the flaw is limited to users with admin rights, an attacker must first authenticate at that privilege level. The vulnerability does not appear in the CISA KEV catalog, and no EPSS score is available, so publicly disclosed exploit data is scarce. Nonetheless, if an admin account is compromised or if an attacker can elevate privileges, the SQL injection can be leveraged with high impact. The high-control scope of the attack vector makes mitigation through patching the highest priority.
OpenCVE Enrichment