---
id: CVE-2026-80517
title: >-
  The WP Ultimate CSV Importer  WordPress plugin before 9.2 does not properly
  validate the file types contained in an uploaded archive nor sanitise their
  content before storing them in a publicly served location, allowing high
  privilege us…
summary: >-
  The WP Ultimate CSV Importer  WordPress plugin before 9.2 does not properly
  validate the file types contained in an uploaded archive nor sanitise their
  content before storing them in a publicly served location, allowing high
  privilege us…
severity: none
cwe:
  - CWE-79
product: WP Ultimate CSV Importer
affected:
  - wp_ultimate_csv_importer >= 7.17 < 9.2
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:42.693'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80517'
references:
  - url: 'https://wpscan.com/vulnerability/2ac66402-2a79-42dd-9056-12c819112f07/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.562Z'
---

## Overview

The WP Ultimate CSV Importer  WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered_html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
