๐Ÿ” CVE Alert

CVE-2026-80518

UNKNOWN 0.0

WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable Log Path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file.

Vendor unknown
Product wp ultimate csv importer
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp ultimate csv importer

Be the first to know when new unknown vulnerabilities affecting unknown wp ultimate csv importer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WP Ultimate CSV Importer
0 < 9.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/80563420-5471-42a9-b022-b3d9792c07aa/

Credits

Ronny Greenberg WPScan