20,000 WordPress Sites Affected by Arbitrary File Upload and Deletion Vulnerabilities in WP Ultimate CSV Importer WordPress Plugin

TLDR: Wordfence's Bug Bounty Program rewards researchers for reporting vulnerabilities. A recent submission uncovered two critical issues in the WP Ultimate CSV Importer plugin (versions ≤ 7.19) that allow authenticated users to upload malicious files and delete key site files, risking site takeover. The vulnerabilities have been patched in version 7.19.1. Users should update immediately. Wordfence protects all users against these threats.

https://www.wordfence.com/blog/2025/03/20000-wordpress-sites-affected-by-arbitrary-file-upload-and-deletion-vulnerabilities-in-wp-ultimate-csv-importer-wordpress-plugin/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top