CVE-2018-20967: Smackcoders Import All Pages, Post Types, Products, Orders, And Users As XML & Csv

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

Affected products

  • Smackcoders Import All Pages, Post Types, Products, Orders, And Users As XML & Csv: before 5.6.1 (fixed in 5.6.1)

Published 2019-08-14. Last modified 2026-06-17.