cleantalk
Vulnerabilities and Security Researches

Import CSV or XML Datafeed With Ease, CVE-2026-80488

CVE, Research URL

CVE-2026-80488

Published on
Aug 29, 2026
Research Description
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
Affected versions
max 9.0.
Status
vulnerable