CVE-2018-20967: Smackcoders Import All Pages, Post Types, Products, Orders, And Users As XML & Csv
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
Affected products
- Smackcoders Import All Pages, Post Types, Products, Orders, And Users As XML & Csv: before 5.6.1 (fixed in 5.6.1)
Published 2019-08-14. Last modified 2026-06-17.