{"id":"CVE-2026-80517","title":"The WP Ultimate CSV Importer  WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege us…","summary":"The WP Ultimate CSV Importer  WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege us…","severity":"none","cwe":["CWE-79"],"product":"WP Ultimate CSV Importer","affected":["wp_ultimate_csv_importer >= 7.17 < 9.2"],"published":"2026-10-03","updated":"2026-10-03","sourceUpdated":"2026-10-03T06:16:42.693","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80517","references":[{"url":"https://wpscan.com/vulnerability/2ac66402-2a79-42dd-9056-12c819112f07/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-03T06:39:57.562Z","slug":"CVE-2026-80517","body":"## Overview\n\nThe WP Ultimate CSV Importer  WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered_html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}