Impact
The vulnerability resides in the WP Ultimate CSV Importer plugin before version 9.2. It fails to validate the MIME types and content of files inside an uploaded ZIP archive and stores them in a publicly accessible location. As a result, an administrator or a site administrator on a multisite installation can inject malicious SVG assets that persist in the site’s media library and are rendered when other stored Cross‑Site Scripting.
Affected Systems
Affected systems include installations of the WP Ultimate CSV Importer plugin with versions earlier than 9.2 running on WordPress. The issue is present in both single‑site and multisite configurations, with the latter allowing site administrators to affect other administrators such as network super admins through the viewed files.
Risk and Exploitability
With a CVSS score of 3.5 and an EPSS score of less than 1%, the vulnerability has low severity and low predicted exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ability for a high‑privilege user to create persistent scripts that run in the browser session of any visitor—including privileged accounts—makes the risk significant. The attack can be executed by uploading a crafted ZIP archive during the normal CSV import workflow, so any administrator who uses the plugin without a recent update is potentially exploitable.
OpenCVE Enrichment