Sceawere

Vulnerability Detail

CVE-2026-80518UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Ultimate CSV Importer Information Disclosure

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
13h ago
Vendor
Unknown
Product
WP Ultimate CSV Importer
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-10-03T06:16:43.003Z",
  "pubdate": "2026-10-03T06:16:43.003Z",
  "executiveSummary": "The WP Ultimate CSV Importer WordPress plugin, specifically versions prior to 9.2, is susceptible to an unauthenticated information disclosure vulnerability.\nThe flaw stems from a predictable storage path for import logs within the WordPress uploads directory, combined with a lack of access controls.\nThis vulnerability allows remote, unauthenticated attackers to retrieve sensitive data, including personally identifiable information (PII) of users imported via CSV files.\nThe impact is significant as it facilitates unauthorized access to private user data, potentially leading to identity theft or further targeted exploitation.\nThe risk is exacerbated by the absence of a site-specific secret or cryptographic salt during the path derivation process, making the log files discoverable via brute-force or directory enumeration techniques.\nNo authentication or specific privileges are required by the attacker to exploit this flaw, as the files are directly accessible via standard web requests over the network.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure implementation of the log storage mechanism within the WP Ultimate CSV Importer plugin. When the plugin performs a CSV import operation, it generates log files to record the progress and outcome of the process. In versions prior to 9.2, the logic responsible for deriving the storage location for these files relies on predictable naming conventions or paths within the WordPress 'uploads' directory.\nCrucially, the plugin fails to incorporate a site-specific secret, hash, or unique identifier when constructing these file paths. By neglecting to obfuscate the storage location, the developer has introduced a deterministic path structure that is globally consistent across all installations. Furthermore, the directory in which these logs are written lacks appropriate server-side access control mechanisms, such as an '.htaccess' file denying direct access or a 'web.config' equivalent, allowing any user with network connectivity to the target server to request these files directly via an HTTP GET request.\nThe attack flow proceeds as follows: First, an attacker identifies a target site running a vulnerable version of the plugin. Because the storage path is predictable, the attacker can systematically attempt to access common file paths in the uploads directory where the plugin is known to deposit logs. Second, upon locating a valid log file URL, the attacker performs an unauthenticated HTTP GET request. Third, because the server does not enforce session validation or authorization checks for these resources, the web server processes the request and returns the contents of the log file to the attacker.\nThe content of these logs often includes detailed information captured during the import process, which may contain sensitive user data such as full names, email addresses, or other metadata extracted from the CSV file. This information is exposed in cleartext, enabling the attacker to scrape and exfiltrate user databases without interacting with the application's administrative interface. The lack of authentication requirement lowers the barrier to entry, allowing for automated, large-scale exploitation across multiple WordPress installations."
}
CVE-2026-80518: WP Ultimate CSV Importer Information Disclosure (LOW Severity, CVSS: 3.7) | Sceawere