Sceawere
Vulnerability Detail
CVE-2026-80517UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Ultimate CSV Importer XSS
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.5
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- WP Ultimate CSV Importer
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered_html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.5",
"pubDate": "2026-10-03T06:16:42.693Z",
"pubdate": "2026-10-03T06:16:42.693Z",
"executiveSummary": "The WP Ultimate CSV Importer WordPress plugin, specifically versions prior to 9.2, contains a critical security flaw involving improper file type validation and lack of content sanitization for uploaded archives.\nThis vulnerability allows high-privilege users, such as administrators, to execute Stored Cross-Site Scripting (XSS) attacks by uploading malicious files.\nIn the context of WordPress Multisite installations, this vulnerability is particularly significant as site administrators, who typically lack the unfiltered_html capability, can bypass this restriction to execute arbitrary scripts in the sessions of other users, including Network Super Admins.\nThe risk implication is high, as the vulnerability facilitates unauthorized script execution within the context of the affected site's origin, potentially leading to session hijacking, administrative action manipulation, or further privilege escalation within the WordPress ecosystem.\nSuccessful exploitation requires the attacker to possess at least administrative privileges, allowing them to utilize the plugin's file import functionality to inject malicious content that is subsequently stored and served in a public location.",
"technicalDetails": "The root cause of this vulnerability lies in the WP Ultimate CSV Importer plugin's handling of uploaded archive files. The plugin fails to perform rigorous validation of the file types contained within an uploaded archive and neglects to sanitize the content of these files before storing them on the server filesystem.\nConsequently, when an archive is processed, the extracted files—which may contain malicious JavaScript payloads—are written to a directory that is served directly by the web server. Because these files are not treated as untrusted input during the storage process, any executable scripts embedded within them are persisted without modification.\nThe attack flow proceeds as follows: First, an authenticated administrator with access to the plugin creates an archive file containing a malicious payload, such as a crafted HTML file with embedded script tags. Second, the attacker uploads this archive via the WP Ultimate CSV Importer's import functionality. Third, the plugin extracts the contents of the archive and stores the malicious file in a publicly accessible directory without proper sanitization or validation of the file's content or MIME type.\nThe exploitation occurs when a victim, such as a Network Super Admin, navigates to the URL where the malicious file is stored. When the victim's browser accesses this file, the web server serves it, and the browser executes the embedded JavaScript within the context of the victim's session. Since the script runs in the context of the victim's browser, it inherits the victim's permissions and access tokens.\nIn WordPress Multisite environments, this is a significant security boundary bypass. Typically, site administrators do not have the unfiltered_html capability, which prevents them from injecting arbitrary HTML or scripts into posts or pages. However, because this vulnerability exploits the plugin's file handling mechanisms to store scripts in a publicly served location, the site administrator effectively circumvents the security controls designed to limit their ability to execute JavaScript in the context of other users.\nThe post-exploitation impact includes the potential for session hijacking, where the attacker steals the session cookie of the victim (e.g., a Network Super Admin), allowing the attacker to impersonate the victim, or performing actions on behalf of the victim, such as altering site configurations, creating new administrator accounts, or exfiltrating sensitive data."
}