WordPress Plugin Vulnerabilities

WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable Log Path

Description

The plugin does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file.

Proof of Concept

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Ronny Greenberg
Submitter
Ronny Greenberg
Verified
Yes

Timeline

Publicly Published
2026-10-01 (about 2 days ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-01 (about 1 day ago)

Other