Skip to main content

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise… (CVE-2026-80517)

0
High
Published: 10/03/2026 (10/03/2026, 06:31:13 UTC)
Source: GCVE Database

Description

The WP Ultimate CSV Importer WordPress plugin versions before 9.2 contain a vulnerability where uploaded archive files are not properly validated for file types nor sanitized before being stored in publicly accessible locations. This flaw allows high privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS). On Multisite WordPress installations, site administrators lacking unfiltered_html capability can exploit this to run scripts in the context of users who view the malicious file, including Network Super Admins.

Affected software

Affected versions
<9.2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:34:37 UTC

Technical Analysis

CVE-2026-80517 affects WP Ultimate CSV Importer WordPress plugin versions prior to 9.2. The vulnerability arises from improper validation and sanitization of file types within uploaded archives, which are then stored in publicly accessible locations. This enables high privilege users, including administrators, to inject stored cross-site scripting payloads. In Multisite environments, site administrators without unfiltered_html capability can exploit this to execute scripts in the sessions of other users, including Network Super Admins.

Potential Impact

Successful exploitation allows high privilege users to execute stored cross-site scripting attacks, potentially compromising the sessions of other users who access the malicious files. In Multisite setups, this extends to Network Super Admins, increasing the risk of widespread administrative compromise.

Mitigation Recommendations

Upgrade the WP Ultimate CSV Importer plugin to version 9.2 or later where this vulnerability is fixed. Until then, restrict high privilege user access to trusted individuals and avoid uploading untrusted archive files. Patch status is not explicitly confirmed in the provided data; verify with the vendor advisory for official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-4qqx-23c4-hcqv
Osv Schema Version
1.4.0
Aliases
["CVE-2026-80517"]
State
PUBLISHED

Threat ID: 6ac13995a43b0b3b89d699b3

Added to database: 10/03/2026, 17:21:25 UTC

Last enriched: 10/03/2026, 17:34:37 UTC

Last updated: 10/04/2026, 01:45:56 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses