CVE-2026-103336: WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/wp-ultimate-csv-importerto a version that resolves this vulnerability.Fixed in 9.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is remotely exploitable without authentication or user interaction, as indicated by the AV:N/AC:L/PR:N/UI:N vector. An attacker can potentially obtain sensitive information exposed through affected plugin behavior.
Which installations are affected?
WP Ultimate CSV Importer versions through 9.1 are affected. The available data does not identify a fixed version or provide configuration-specific conditions.
What is the impact of successful exploitation?
Successful exploitation can expose sensitive data. The supplied severity vector indicates low confidentiality impact and no stated integrity or availability impact.