Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Kawagishi Kouhei

#56539de 57,427
3.5CVSS total
Vulnerabilidades · 1
PT-2026-104521
3.5
2026-10-03
Undefined · Undefined · CVE-2026-80517
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.