CVE-2026-80488

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

  • Published Aug 29, 2026
  • CVSS 4.1 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-80488 at the National Vulnerability Database