CVE-2026-65461
Received Received - Intake

Arbitrary File Upload in Really Simple CSV Importer

Vulnerability report for CVE-2026-65461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Patchstack

Description

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patchstack really_simple_csv_importer to 1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Arbitrary File Upload vulnerability in the Really Simple CSV Importer WordPress plugin versions 1.3 and earlier. It allows attackers with administrator or developer privileges to upload any file type to a website, potentially including malicious files like backdoors for further exploitation.

Detection Guidance

Check if the Really Simple CSV Importer plugin version is 1.3 or earlier. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin directory for version details.

Impact Analysis

An attacker could upload malicious files to your website, gaining unauthorized access or control. This could lead to data theft, website defacement, or further compromise of your server. The high CVSS score of 9.1 indicates significant risk if exploited.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements under GDPR, HIPAA, or other regulations. Organizations may face legal penalties, reputational damage, and loss of customer trust if exploited.

Mitigation Strategies

Update the Really Simple CSV Importer plugin to version 1.3.1 or later immediately. If updating is not possible, contact your hosting provider or web developer for assistance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65461. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart