Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 7.9.8

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to a security issue that could allow attackers with certain permissions to create a file on the server and run code on it. This issue affects all versions up to and including 7.9.8. The author has fixed this issue by removing the ability for authors and editors to import files. However, administrators can still create php files, so the plugin should be used with care.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.