Executive brief
A popular WordPress plugin used for importing and exporting data via CSV, XML, and Excel files contains a critical security flaw. An attacker with basic user access (such as a Subscriber) can exploit this to run unauthorized commands on the website's server. This could lead to a full takeover of the site, theft of sensitive customer data, or complete service disruption.
Technical details
The vulnerability is classified as Remote Code Execution (RCE) via Code Injection (CWE-94). It stems from missing capability checks on several AJAX handlers, including install_addon, saveMappedFields, and StartImport. Because the plugin's security nonce is exposed to any authenticated user capable of loading an admin page, a Subscriber-level user can bypass intended restrictions. An attacker can install the WooCommerce add-on, inject malicious PHP expressions into the 'MappedFields' parameter, and trigger their execution through the eval() function within ImportHelpers::get_meta_values(). A patch has been identified in changeset 3591135.
Affected products
- Smackcoders WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel Up to and including 8.0.1
Timeline
- 2026-07-11: advisory: NVD publication date
- 2026-07-11: disclosed: Wordfence advisory published
References
- https://plugins.trac.wordpress.org/browser/wp-ultimate-csv-importer/tags/8.0.1/InstallAddons.php
- https://plugins.trac.wordpress.org/browser/wp-ultimate-csv-importer/tags/8.0.1/SaveMapping.php
- https://plugins.trac.wordpress.org/browser/wp-ultimate-csv-importer/tags/8.0.1/SaveMapping.php
- https://plugins.trac.wordpress.org/browser/wp-ultimate-csv-importer/tags/8.0.1/wp-ultimate-csv-importer.php
- https://plugins.trac.wordpress.org/changeset/3591135/wp-ultimate-csv-importer
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e89fc348-1146-4593-8bf5-127f783ab786?source=cve