CVE-2026-80518: WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable Log Path
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a CSV file.
Affected Software
Event History
Frequently Asked Questions
Who can retrieve the exposed data?
Unauthenticated attackers can retrieve personal data for users imported from a CSV file. No login or other authentication is required.
What must be true for a site to be exposed?
The site must use a version of WP Ultimate CSV Importer before 9.2 and have import logs written under the uploads directory. The issue affects logs containing data from imported user CSV files.
How is the data accessed?
The plugin derives its import-log storage location without a site-specific secret and does not block direct access to the logs. An attacker can use the predictable log path to request the files directly.