PT-2022-25284 · Xylus Themes · Xylus Themes Wp Smart Import

Nguyen Anh Tien

·

Published

2022-12-06

·

Updated

2022-12-07

·

CVE-2022-40209

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Xylus Themes WP Smart Import plugin versions 1.0.2 and earlier
Description The issue is related to an Unauth. Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability affects the Xylus Themes WP Smart Import plugin on WordPress, allowing for potential malicious script injection without proper authentication.
Recommendations For Xylus Themes WP Smart Import plugin versions 1.0.2 and earlier, update to a version later than 1.0.2 to resolve the issue. At the moment, there is no information about additional mitigation measures.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40209

Affected Products

Xylus Themes Wp Smart Import