SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80488

MEDIUM · CVSS 4.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WP Ultimate CSV Importer plugin for WordPress versions prior to 9.0 is vulnerable due to inadequate sanitization and escaping of imported field values, potentially enabling high-privilege users, such as administrators, to execute SQL injection attacks. This vulnerability poses a significant risk to the integrity of the database and could lead to unauthorized data manipulation or exposure. WordPress site administrators using this plugin should prioritize updating to version 9.0 or later to mitigate this risk.

CVE
CVE-2026-80488
Severity
MEDIUM
CVSS
4.1
EPSS
0.19%
WordPress

Original NVD Description

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.