Description
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered_html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.
Published: 2026-10-03
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Update Plugin
AI Analysis

Impact

The vulnerability resides in the WP Ultimate CSV Importer plugin before version 9.2. It fails to validate the MIME types and content of files inside an uploaded ZIP archive and stores them in a publicly accessible location. As a result, an administrator or a site administrator on a multisite installation can inject malicious SVG assets that persist in the site’s media library and are rendered when other stored Cross‑Site Scripting.

Affected Systems

Affected systems include installations of the WP Ultimate CSV Importer plugin with versions earlier than 9.2 running on WordPress. The issue is present in both single‑site and multisite configurations, with the latter allowing site administrators to affect other administrators such as network super admins through the viewed files.

Risk and Exploitability

With a CVSS score of 3.5 and an EPSS score of less than 1%, the vulnerability has low severity and low predicted exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ability for a high‑privilege user to create persistent scripts that run in the browser session of any visitor—including privileged accounts—makes the risk significant. The attack can be executed by uploading a crafted ZIP archive during the normal CSV import workflow, so any administrator who uses the plugin without a recent update is potentially exploitable.

Generated by OpenCVE AI on October 3, 2026 at 17:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Ultimate CSV Importer to version 9.2 or later.
  • Delete or back up previously uploaded archive contents that were stored via the plugin.
  • Configure the server to reject or sanitize SVG files during upload, or restrict ZIP uploads to trusted administrators only.

Generated by OpenCVE AI on October 3, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered_html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.
Title WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Upload
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:22.581Z

Reserved: 2026-08-26T14:31:03.074Z

Link: CVE-2026-80517

cve-icon Vulnrichment

Updated: 2026-10-03T15:06:07.444Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:42.693

Modified: 2026-10-03T16:16:38.697

Link: CVE-2026-80517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T17:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')