Medium severity4.3NVD Advisory· Published Oct 5, 2023· Updated Jun 17, 2026
CVE-2015-10125
CVE-2015-10125
Description
A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifier of the patch is 13c30af721d3f989caac72dd0f56cf0dc40fad7e. It is recommended to upgrade the affected component. The identifier VDB-241317 was assigned to this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:smackcoders:import_all_pages\,_post_types\,_products\,_orders\,_and_users_as_xml_\&_csv:*:*:*:*:*:wordpress:*:*Range: <3.7.3
- Range: <3.7.3
Patches
Vulnerability mechanics
References
4- github.com/wp-plugins/wp-ultimate-csv-importer/commit/13c30af721d3f989caac72dd0f56cf0dc40fad7envdPatch
- vuldb.comnvdThird Party Advisory
- vuldb.comnvdThird Party Advisory
- github.com/wp-plugins/wp-ultimate-csv-importer/releases/tag/3.7.3nvdRelease Notes
News mentions
0No linked articles in our index yet.