Description
WordPress Plugin Import all XML, CSV & TXT into WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete arbitrary options from the blog. WordPress Plugin Import all XML, CSV & TXT into WordPress version 6.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.4.2 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:06A98F51-E581-4E42-8287-7C18254D100C
https://plugins.svn.wordpress.org/wp-ultimate-csv-importer/trunk/Readme.txt
Related Vulnerabilities
WordPress Plugin Total Security Multiple Unspecified Vulnerabilities (3.4.1)
WordPress Plugin Social Share Buttons-Social Pug Multiple Unspecified Vulnerabilities (1.3.1)
WordPress Plugin PitchPrint Arbitrary File Upload (7.2.1)
WordPress Plugin AGP Font Awesome Collection Cross-Site Scripting (2.7.2)
WordPress 4.4.x Cross-Site Scripting Vulnerability (4.4 - 4.4.2)