Description
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file.
Published: 2026-10-03
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Personal Data Disclosure
Action: Assess Impact
AI Analysis

Impact

WP Ultimate CSV Importer, a WordPress plugin, writes import logs to the uploads directory using a predictable file path and does not apply any site‑specific secret or access control. This design flaw allows an unauthenticated attacker to request the log file directly and obtain any personal data that was imported from a CSV file. The exposure of such information constitutes an information disclosure vulnerability that could affect the confidentiality of user data.

Affected Systems

The vulnerability impacts installations of WP Ultimate CSV Importer plugin versions earlier than 9.2. Any WordPress site that has imported user data via this plugin before the upgrade is potentially affected.

Risk and Exploitability

Because the flaw permits simple HTTP requests to read log files, the attack vector is unauthenticated and does not require elevated privileges. The CVSS score is 3.7, but the risk is high due to potential privacy violations. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ability to leak sensitive data without authentication makes the risk significant.

Generated by OpenCVE AI on October 3, 2026 at 19:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Ultimate CSV Importer to version 9.2 or later, which addresses the log path predictability flaw.
  • Configure the web server or WordPress settings to deny direct HTTP access to the uploads directory or to the specific log files, such as adding .htaccess rules or web‑server directives to reject GET requests for these files.
  • Implement a site‑specific secret or hash when constructing log file paths and enforce proper access controls (e.g., role‑based restrictions or file‑system permissions) so that only authorized users can read the logs.

Generated by OpenCVE AI on October 3, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file.
Title WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable Log Path
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:22.461Z

Reserved: 2026-08-26T14:31:11.116Z

Link: CVE-2026-80518

cve-icon Vulnrichment

Updated: 2026-10-03T15:05:53.907Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:43.003

Modified: 2026-10-03T16:16:38.843

Link: CVE-2026-80518

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T19:30:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor