PT-2026-57378 · WordPress · Wp Ultimate Csv Importer

·

CVE-2026-13353

·

Published

2026-07-11

·

Updated

2026-07-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel versions prior to 8.0.2
Description Authenticated attackers with subscriber-level access and above can achieve Remote Code Execution (RCE) due to missing capability checks on the AJAX handlers for install addon, saveMappedFields, and StartImport. The plugin nonce is exposed to any authenticated user capable of loading an admin page, allowing an attacker to install the Import WooCommerce add-on and persist malicious PHP expressions via the MappedFields parameter. These expressions are subsequently triggered through the eval() function within ImportHelpers::get meta values(). RCE is a security flaw that allows an attacker to execute arbitrary commands on the host server.
Recommendations Update to version 8.0.2 or later.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13353

Affected Products

Wp Ultimate Csv Importer