Reflected Cross-Site Scripting Vulnerability in WP Smart Import Plugin for WordPress
CVE-2024-12701
6.1MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 4 January 2025
Summary
The WP Smart Import plugin for WordPress contains a vulnerability that allows for reflected cross-site scripting via the 'page' parameter. This weakness exists in all versions up to and including 1.1.2, primarily due to inadequate input sanitization and output escaping. Unauthenticated attackers may exploit this vulnerability by injecting arbitrary web scripts, provided they can convince a user to click on a manipulated link, leading to potential malicious actions performed in the context of the affected user's session.
Affected Version(s)
WP Smart Import : Import any XML File to WordPress * <= 1.1.2
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Colin Xu