Impact
WP Ultimate CSV Importer, a WordPress plugin, writes import logs to the uploads directory using a predictable file path and does not apply any site‑specific secret or access control. This design flaw allows an unauthenticated attacker to request the log file directly and obtain any personal data that was imported from a CSV file. The exposure of such information constitutes an information disclosure vulnerability that could affect the confidentiality of user data.
Affected Systems
The vulnerability impacts installations of WP Ultimate CSV Importer plugin versions earlier than 9.2. Any WordPress site that has imported user data via this plugin before the upgrade is potentially affected.
Risk and Exploitability
Because the flaw permits simple HTTP requests to read log files, the attack vector is unauthenticated and does not require elevated privileges. The CVSS score is 3.7, but the risk is high due to potential privacy violations. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ability to leak sensitive data without authentication makes the risk significant.
OpenCVE Enrichment