Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smackcoders
Smackcoders wp Import – Ultimate Csv Xml Importer For Wordpress Wordpress Wordpress wordpress |
|
| Vendors & Products |
Smackcoders
Smackcoders wp Import – Ultimate Csv Xml Importer For Wordpress Wordpress Wordpress wordpress |
Wed, 18 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.37. This is due to insufficient escaping on the `file_name` parameter which is stored in the database during file upload and later used in raw SQL queries without proper sanitization. This makes it possible for authenticated attackers with Subscriber-level access or higher to append additional SQL queries into already existing queries via a malicious filename, which can be used to extract sensitive information from the database. The vulnerability can only be exploited when the 'Single Import/Export' option is enabled, and the server is running a PHP version < 8.0. | |
| Title | WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-18T20:24:06.821Z
Reserved: 2026-01-21T23:41:23.912Z
Link: CVE-2026-1317
Updated: 2026-02-18T20:24:03.645Z
Status : Awaiting Analysis
Published: 2026-02-18T13:16:20.167
Modified: 2026-02-18T17:51:53.510
Link: CVE-2026-1317
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:20:15Z