Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities associated with WP Ultimate CSV Importer, a popular WordPress plugin developed by CodeAstro, focusing on weaknesses in its data import and file handling mechanisms. The content aggregates publicly disclosed security issues affecting this specific product, encompassing flaws related to insecure direct object references, lack of input validation, and potential cross-site scripting vectors. The timeline covered includes all recorded advisories and vulnerability reports from the plugin’s initial release through to the most recent updates, ensuring a comprehensive historical perspective on its security posture. Visitors to this resource can track the vendor’s advisory history to understand how security incidents were reported and resolved over time. Users can also explore specific weakness classes to gain a deeper technical understanding of how improper handling of CSV, XML, and Excel files can lead to exploitation. Furthermore, the page allows for a detailed look-up of the product’s vulnerability history, providing context on the frequency and severity of past security breaches. This structured overview aids security researchers, site administrators, and developers in assessing the current risk level and implementing appropriate mitigation strategies. By consolidating these findings in one location, the resource facilitates better-informed decisions regarding plugin selection, version upgrades, and server-side hardening procedures necessary to protect WordPress installations from the specific threats posed by this tool.

Vendor: smackcoders

CVE IDTitleCVSSSeverityPublished
CVE-2026-1317 WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name CWE-89 6.5 Medium2026-02-18
CVE-2025-14627 WP Import – Ultimate CSV XML Importer for WordPress <= 7.35 - Authenticated (Contributor+) Server-Side Request Forgery via Bitly Shortlink Bypass CWE-918 6.4 Medium2026-01-01
CVE-2025-13145 WP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import CWE-502 7.2 High2025-11-19
CVE-2025-12732 WP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information Exposure CWE-200 4.3 Medium2025-11-12
CVE-2025-10058 WP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Authenticated (Subscriber+) Arbitrary File Deletion CWE-73 8.1 High2025-09-17
CVE-2025-10040 WP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Missing Authorization to Authenticated (Subscriber+) FTP/SFTP Credential Exposure CWE-862 7.7 High2025-09-10
CVE-2025-2008 Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High2025-04-01
CVE-2025-2007 Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Deletion CWE-23 8.1 High2025-04-01
CVE-2023-4142 WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution CWE-94 8.0 High2023-08-04
CVE-2023-4141 WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution CWE-94 8.0 High2023-08-04
CVE-2023-4139 WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing CWE-200 7.5 High2023-08-04
CVE-2023-4140 WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation CWE-269 6.6 Medium2023-08-04

All 12 known CVE vulnerabilities affecting WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress with full Chinese analysis, references, and POCs where available.