CVE-2026-80517
Received Received - Intake

WP Ultimate CSV Importer Stored XSS via File Upload

Vulnerability report for CVE-2026-80517, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: WPScan

Description

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered_html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_ultimate_csv_importer wp_ultimate_csv_importer From 7.17 (inc) to 9.2 (exc)
wp_ultimate_csv_importer wp_ultimate_csv_importer to 9.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the WP Ultimate CSV Importer WordPress plugin versions 7.17 to 9.1. It occurs because the plugin fails to properly validate file types in uploaded ZIP archives and does not sanitize their content before storing them in a publicly accessible location.

Detection Guidance

Check if the WP Ultimate CSV Importer plugin version is between 7.17 and 9.1. Inspect uploaded ZIP archives for SVG files stored in publicly accessible locations. Review server logs for unusual file uploads or script executions.

Impact Analysis

High-privilege users like administrators can exploit this to upload malicious SVG files. These files can then execute scripts in the sessions of users who view them, including Network Super Admins on Multisite installations where site administrators lack the unfiltered_html capability.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA due to the risk of stored cross-site scripting (XSS). Unauthorized script execution in user sessions may lead to data breaches or unauthorized access to sensitive information, which are key concerns under these regulations.

Mitigation Strategies

Update the WP Ultimate CSV Importer plugin to version 9.2 or later immediately. Remove any suspicious SVG files from publicly accessible directories. Restrict file upload permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80517. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart