Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress WP Ultimate CSV Importer plugin to the latest available version (at least 9.2).
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1. | |
| Title | WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-01T13:56:29.020Z
Reserved: 2026-09-30T12:43:33.092Z
Link: CVE-2026-103336
No data.
Status : Deferred
Published: 2026-10-01T12:17:14.930
Modified: 2026-10-01T12:40:28.083
Link: CVE-2026-103336
No data.
OpenCVE Enrichment
Updated: 2026-10-01T13:30:06Z
-
CWE-201
Insertion of Sensitive Information Into Sent Data