Access violation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 7.9.8

The WordPress Ultimate CSV Importer plugin is vulnerable to a security issue in versions up to, and including, 7.9.8. This flaw could allow attackers, who have at least minimal permissions like an author, to modify their user role if the administrator has previously enabled them in the plugin settings. This is done by supplying the ‘wp_capabilities->cus1’ parameter.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.