WordPress · Wp Ultimate Csv Importer · CVE-2026-80488
**Name of the Vulnerable Software and Affected Versions**
WP Ultimate CSV Importer versions prior to 9.0
**Description**
Insufficient sanitization and escaping of imported field values before their use in a SQL statement allows high privilege users, such as administrators, to perform SQL injection attacks. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to or manipulation of the database.
**Recommendations**
Update to version 9.0 or later.