Patchstack Critical RCE Vulnerabilities Discovered in Npm tidgi and WP Ultimate CSV Importer
Article Content
- •Critical RCE vulnerabilities found in Npm tidgi and WP Ultimate CSV Importer plugins.
- •Immediate updates are required to prevent potential backdoor access to affected websites.
- •Patchstack has provided mitigation rules for the WP Ultimate CSV Importer until updates are applied.
Two remote code execution (RCE) vulnerabilities have been identified in popular plugins: Npm tidgi and WP Ultimate CSV Importer. The Npm tidgi vulnerability allows privileged users to execute commands via malicious links or crafted pages. Similarly, the WP Ultimate CSV Importer plugin has a missing authorization flaw that also permits command execution by authenticated users. Both vulnerabilities could enable attackers to gain backdoor access to affected websites. Users are advised to update the plugins immediately to mitigate risks. The CVSS scoring system is mentioned but deemed not ideal for WordPress vulnerabilities. Patchstack has issued mitigation rules for the WP Ultimate CSV Importer until updates are applied. The Npm tidgi vulnerability was reported on July 14, 2026, while the WP Ultimate CSV Importer vulnerability was reported on July 16, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…