CVE-2026-80517 UNKNOWN

CVE-2026-80517

Published: 2026-10-03

Description

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered_html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…