Junglewise Threat Intelligence

CVE-2026-65461: Webnosoudanjo Really Simple CSV Importer arbitrary file upload

CVE-2026-65461 · Severity: critical · CVSS 9.1 · Published 2026-07-23

Executive brief

Really Simple CSV Importer is a WordPress plugin used to import site content from CSV files. A security vulnerability allows an administrative user to upload malicious files, such as web shells, directly to the server. This could lead to a complete takeover of the website and the underlying server environment.

Technical details

The Really Simple CSV Importer plugin for WordPress (versions <= 1.3) contains an unrestricted file upload vulnerability (CWE-434). The flaw allows an authenticated user with Administrator-level privileges to upload executable files, such as PHP scripts, to the server. Because the plugin does not properly validate file extensions or content types during the import process, an attacker can achieve remote code execution (RCE). This vulnerability is mitigated by the requirement for high-level administrative access, though it poses a significant risk in multi-admin environments or via Cross-Site Request Forgery (CSRF) if not properly protected. The issue is addressed in version 1.3.1.

Affected products

  • Webの相談所 (Webnosoudanjo) Really Simple CSV Importer <= 1.3

Timeline

  • 2026-06-30: other: Reported by researcher Ananda Dhakal
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date

References