Reflected Cross-Site Scripting Vulnerability in WP Smart Import Plugin for WordPress
CVE-2024-12701
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 4 January 2025
What is CVE-2024-12701?
The WP Smart Import plugin for WordPress contains a vulnerability that allows for reflected cross-site scripting via the 'page' parameter. This weakness exists in all versions up to and including 1.1.2, primarily due to inadequate input sanitization and output escaping. Unauthenticated attackers may exploit this vulnerability by injecting arbitrary web scripts, provided they can convince a user to click on a manipulated link, leading to potential malicious actions performed in the context of the affected user's session.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Smart Import : Import any XML File to WordPress * <= 1.1.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved