Unrated severityNVD Advisory· Published Oct 3, 2026
CVE-2026-80517
CVE-2026-80517
Description
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite installations a site Administrator does not hold the unfiltered_html capability, so this lets them run scripts in the session of users who view the file, including Network Super Admins.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <9.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.