CVE-2026-80488: WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields
Published Aug 29, 2026
·Updated
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
Affected Software
1 affected component
WP Ultimate CSV Importer WordPress plugin<9.0
Event History
Aug 29, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness