Cross-Site Request Forgery Vulnerability in AA-Team WordPress Movies Bulk Importer
CVE-2026-22359

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 January 2026

What is CVE-2026-22359?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the AA-Team WordPress Movies Bulk Importer plugin. This security flaw enables an attacker to perform unauthorized actions on behalf of an unsuspecting user, which could lead to unauthorized data alterations or exposure. The vulnerability affects all versions of the plugin up to and including 1.0, posing risks to users who have not updated their plugins.

Affected Version(s)

Wordpress Movies Bulk Importer <= n/a

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program
.