Other
6 records22.2%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 27 vulnerability records associated with WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel, published between 2015 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 4 | |
| 2018 | 1 | |
| 2019 | 1 | |
| 2022 | 7 | |
| 2023 | 4 | |
| 2025 | 7 | |
| 2026 | 3 |
| Severity | Records | Share |
|---|---|---|
| High | 16 | 59.3% |
| Medium | 11 | 40.7% |
First: 2022. Latest: 2026.
First: 2022. Latest: 2026.
First: 2015. Latest: 2025.
First: 2015. Latest: 2022.
First: 2015. Latest: 2019.
First: 2022. Latest: 2025.
First: 2022. Latest: 2026.
First: 2025. Latest: 2025.
First: 2015. Latest: 2015.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
8.17.387.367.347.33.17.297.287.20.17.19.17.9.96.5.86.5.36.4.36.4.26.4.15.6.13.8.83.8.13.7.33.7.13.6.75Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-8.0.1 | WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter | July 10, 2026 | 8.1 | High |
*-7.37 | WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name | February 17, 2026 | 7.38 | Medium |
*-7.35 | WP Import – Ultimate CSV XML Importer for WordPress <= 7.35 - Authenticated (Contributor+) Server-Side Request Forgery via Bitly Shortlink Bypass | January 1, 2026 | 7.36 | Medium |
*-7.33.1 | WP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import | November 18, 2025 | 7.34 | High |
*-7.33 | WP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information Exposure | November 11, 2025 | 7.33.1 | Medium |
7.20-7.28 | WP Import – Ultimate CSV XML Importer for WordPress 7.20 - 7.28 - Authenticated (Subscriber+) Remote Code Execution via Code Injection | September 16, 2025 | 7.29 | High |
*-7.27 | WP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Authenticated (Subscriber+) Arbitrary File Deletion | September 16, 2025 | 7.28 | High |
*-7.27 | WP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Missing Authorization to Authenticated (Subscriber+) FTP/SFTP Credential Exposure | September 9, 2025 | 7.28 | High |
7.20 | Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Upload | March 31, 2025 | 7.19.1, 7.20.1 | High |
*-7.19 | Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Upload | March 31, 2025 | 7.19.1, 7.20.1 | High |
7.20 | Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Deletion | March 25, 2025 | 7.19.1, 7.20.1 | High |
*-7.19 | Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Deletion | March 25, 2025 | 7.19.1, 7.20.1 | High |
*-7.9.8 | WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution | August 3, 2023 | 7.9.9 | High |
*-7.9.8 | WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution | August 3, 2023 | 7.9.9 | High |
*-7.9.8 | WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing | August 3, 2023 | 7.9.9 | High |
*-7.9.8 | WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation | August 3, 2023 | 7.9.9 | Medium |
*-6.5.7 | WP Ultimate CSV Importer <= 6.5.7 - Missing Authorization | September 20, 2022 | 6.5.8 | Medium |
*-6.5.7 | WP Ultimate CSV Importer <= 6.5.7 - Authenticated (Administrator+) SQL Injection | September 20, 2022 | 6.5.8 | High |
*-6.5.2 | WP Ultimate CSV Importer <= 6.5.2 - Server-Side Request Forgery | June 2, 2022 | 6.5.3 | Medium |
[*, 6.4.3) | WP Ultimate CSV Importer <= 6.4.2 - Admin+ Stored Cross-Site Scripting | January 26, 2022 | 6.4.3 | Medium |
*-6.4.1 | Import all XML, CSV & TXT into WordPress < 6.4.2 - Missing Authorization | January 17, 2022 | 6.4.2 | High |
*-6.4.0 | WP Ultimate CSV Importer <= 6.4.0 - Arbitrary File Upload | January 12, 2022 | 6.4.1 | High |
[*, 6.4.1) | Easy Drag And drop All Import : WP Ultimate CSV Importer < 6.4.1 - Missing Authorization Checks | January 12, 2022 | 6.4.1 | Medium |
*-5.6 | Easy Drag And drop All Import : WP Ultimate CSV Importer <= 5.6 - Cross-Site Request Forgery | August 13, 2019 | 5.6.1 | High |
[*, 3.8.8) | Import Export All WordPress Images, Users & Post Types <= 3.8.7 - Reflected Cross-Site Scripting | January 27, 2018 | 3.8.8 | Medium |
Selected source records
Published: July 10, 2026
Published: February 17, 2026
Published: January 1, 2026
Published: November 18, 2025
Published: November 11, 2025
Published: September 16, 2025
Published: September 16, 2025
Published: September 9, 2025
Published: September 16, 2025
Published: March 31, 2025
Published: August 13, 2019
Published: January 12, 2022
Published: July 10, 2026
Published: March 25, 2025
Published: September 16, 2025
Published: August 3, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.