Sceawere
Vulnerability Detail
CVE-2026-80518UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Ultimate CSV Importer Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- WP Ultimate CSV Importer
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-10-03T06:16:43.003Z",
"pubdate": "2026-10-03T06:16:43.003Z",
"executiveSummary": "The WP Ultimate CSV Importer WordPress plugin, specifically versions prior to 9.2, is susceptible to an unauthenticated information disclosure vulnerability.\nThe flaw stems from a predictable storage path for import logs within the WordPress uploads directory, combined with a lack of access controls.\nThis vulnerability allows remote, unauthenticated attackers to retrieve sensitive data, including personally identifiable information (PII) of users imported via CSV files.\nThe impact is significant as it facilitates unauthorized access to private user data, potentially leading to identity theft or further targeted exploitation.\nThe risk is exacerbated by the absence of a site-specific secret or cryptographic salt during the path derivation process, making the log files discoverable via brute-force or directory enumeration techniques.\nNo authentication or specific privileges are required by the attacker to exploit this flaw, as the files are directly accessible via standard web requests over the network.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure implementation of the log storage mechanism within the WP Ultimate CSV Importer plugin. When the plugin performs a CSV import operation, it generates log files to record the progress and outcome of the process. In versions prior to 9.2, the logic responsible for deriving the storage location for these files relies on predictable naming conventions or paths within the WordPress 'uploads' directory.\nCrucially, the plugin fails to incorporate a site-specific secret, hash, or unique identifier when constructing these file paths. By neglecting to obfuscate the storage location, the developer has introduced a deterministic path structure that is globally consistent across all installations. Furthermore, the directory in which these logs are written lacks appropriate server-side access control mechanisms, such as an '.htaccess' file denying direct access or a 'web.config' equivalent, allowing any user with network connectivity to the target server to request these files directly via an HTTP GET request.\nThe attack flow proceeds as follows: First, an attacker identifies a target site running a vulnerable version of the plugin. Because the storage path is predictable, the attacker can systematically attempt to access common file paths in the uploads directory where the plugin is known to deposit logs. Second, upon locating a valid log file URL, the attacker performs an unauthenticated HTTP GET request. Third, because the server does not enforce session validation or authorization checks for these resources, the web server processes the request and returns the contents of the log file to the attacker.\nThe content of these logs often includes detailed information captured during the import process, which may contain sensitive user data such as full names, email addresses, or other metadata extracted from the CSV file. This information is exposed in cleartext, enabling the attacker to scrape and exfiltrate user databases without interacting with the application's administrative interface. The lack of authentication requirement lowers the barrier to entry, allowing for automated, large-scale exploitation across multiple WordPress installations."
}