Input validation vulnerability in Import All Pages, Post types, Products, Orders, and Users as XML & CSV 7.9.8

The WordPress Ultimate CSV Importer plugin, which is used to import files into WordPress websites, has a security vulnerability in versions up to and including 7.9.8. This vulnerability allows anyone with author-level or higher permissions (if the administrator had previously granted access in the plugin settings) to execute code on the server. The plugin’s author has fixed this by removing the ability for authors and editors to import files. However, it still leaves open the possibility of remote code execution for site administrators. Be cautious when using this plugin.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.