CVE-2026-80488 PUBLISHED

WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields

Assigner: WPScan
Reserved: 26.08.2026 Published: 29.08.2026 Updated: 29.08.2026

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

Product Status

Vendor Unknown
Product WP Ultimate CSV Importer
Versions Default: unaffected
  • affected from 0 to 9.0 (excl.)

Credits

  • Jaan Buerms finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE