The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise… (CVE-2026-80517)
The WP Ultimate CSV Importer WordPress plugin versions before 9.2 contain a vulnerability where uploaded archive files are not properly validated for file types nor sanitized before being stored in publicly accessible locations. This flaw allows high privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS). On Multisite WordPress installations, site administrators lacking unfiltered_html capability can exploit this to run scripts in the context of users who view the malicious file, including Network Super Admins.
AI Analysis
Technical Summary
CVE-2026-80517 affects WP Ultimate CSV Importer WordPress plugin versions prior to 9.2. The vulnerability arises from improper validation and sanitization of file types within uploaded archives, which are then stored in publicly accessible locations. This enables high privilege users, including administrators, to inject stored cross-site scripting payloads. In Multisite environments, site administrators without unfiltered_html capability can exploit this to execute scripts in the sessions of other users, including Network Super Admins.
Potential Impact
Successful exploitation allows high privilege users to execute stored cross-site scripting attacks, potentially compromising the sessions of other users who access the malicious files. In Multisite setups, this extends to Network Super Admins, increasing the risk of widespread administrative compromise.
Mitigation Recommendations
Upgrade the WP Ultimate CSV Importer plugin to version 9.2 or later where this vulnerability is fixed. Until then, restrict high privilege user access to trusted individuals and avoid uploading untrusted archive files. Patch status is not explicitly confirmed in the provided data; verify with the vendor advisory for official fixes.
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise… (CVE-2026-80517)
Description
The WP Ultimate CSV Importer WordPress plugin versions before 9.2 contain a vulnerability where uploaded archive files are not properly validated for file types nor sanitized before being stored in publicly accessible locations. This flaw allows high privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS). On Multisite WordPress installations, site administrators lacking unfiltered_html capability can exploit this to run scripts in the context of users who view the malicious file, including Network Super Admins.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-80517 affects WP Ultimate CSV Importer WordPress plugin versions prior to 9.2. The vulnerability arises from improper validation and sanitization of file types within uploaded archives, which are then stored in publicly accessible locations. This enables high privilege users, including administrators, to inject stored cross-site scripting payloads. In Multisite environments, site administrators without unfiltered_html capability can exploit this to execute scripts in the sessions of other users, including Network Super Admins.
Potential Impact
Successful exploitation allows high privilege users to execute stored cross-site scripting attacks, potentially compromising the sessions of other users who access the malicious files. In Multisite setups, this extends to Network Super Admins, increasing the risk of widespread administrative compromise.
Mitigation Recommendations
Upgrade the WP Ultimate CSV Importer plugin to version 9.2 or later where this vulnerability is fixed. Until then, restrict high privilege user access to trusted individuals and avoid uploading untrusted archive files. Patch status is not explicitly confirmed in the provided data; verify with the vendor advisory for official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4qqx-23c4-hcqv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-80517"]
- State
- PUBLISHED
Threat ID: 6ac13995a43b0b3b89d699b3
Added to database: 10/03/2026, 17:21:25 UTC
Last enriched: 10/03/2026, 17:34:37 UTC
Last updated: 10/04/2026, 01:45:56 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.