Sensitive Data Exposure in WP Ultimate CSV Importer by Smackcoders Inc.
CVE-2026-103336

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-103336?

The WP Ultimate CSV Importer developed by Smackcoders Inc. is affected by a vulnerability that allows unauthorized retrieval of embedded sensitive information. This issue impacts all versions from n/a up to 9.1, posing a risk to data security and potentially exposing critical user data. Users of this plugin should assess their current configurations and take necessary actions to mitigate any risks associated with this vulnerability.

Affected Version(s)

WP Ultimate CSV Importer 0 <= 9.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.