Junglewise Threat Intelligence

CVE-2026-13353: Smackcoders WP Ultimate CSV Importer remote code execution

CVE-2026-13353 · Severity: high · CVSS 8.8 · Published 2026-07-11

Executive brief

A popular WordPress plugin used for importing and exporting data via CSV, XML, and Excel files contains a critical security flaw. An attacker with basic user access (such as a Subscriber) can exploit this to run unauthorized commands on the website's server. This could lead to a full takeover of the site, theft of sensitive customer data, or complete service disruption.

Technical details

The vulnerability is classified as Remote Code Execution (RCE) via Code Injection (CWE-94). It stems from missing capability checks on several AJAX handlers, including install_addon, saveMappedFields, and StartImport. Because the plugin's security nonce is exposed to any authenticated user capable of loading an admin page, a Subscriber-level user can bypass intended restrictions. An attacker can install the WooCommerce add-on, inject malicious PHP expressions into the 'MappedFields' parameter, and trigger their execution through the eval() function within ImportHelpers::get_meta_values(). A patch has been identified in changeset 3591135.

Affected products

  • Smackcoders WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel Up to and including 8.0.1

Timeline

  • 2026-07-11: advisory: NVD publication date
  • 2026-07-11: disclosed: Wordfence advisory published

References