PT-2026-57378 · WordPress · Wp Ultimate Csv Importer
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel versions prior to 8.0.2
Description
Authenticated attackers with subscriber-level access and above can achieve Remote Code Execution (RCE) due to missing capability checks on the AJAX handlers for
install addon, saveMappedFields, and StartImport. The plugin nonce is exposed to any authenticated user capable of loading an admin page, allowing an attacker to install the Import WooCommerce add-on and persist malicious PHP expressions via the MappedFields parameter. These expressions are subsequently triggered through the eval() function within ImportHelpers::get meta values(). RCE is a security flaw that allows an attacker to execute arbitrary commands on the host server.Recommendations
Update to version 8.0.2 or later.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Ultimate Csv Importer