Cross-Site Request Forgery Vulnerability in AA-Team WordPress Movies Bulk Importer
CVE-2026-22359
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 January 2026
What is CVE-2026-22359?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the AA-Team WordPress Movies Bulk Importer plugin. This security flaw enables an attacker to perform unauthorized actions on behalf of an unsuspecting user, which could lead to unauthorized data alterations or exposure. The vulnerability affects all versions of the plugin up to and including 1.0, posing risks to users who have not updated their plugins.
Affected Version(s)
Wordpress Movies Bulk Importer <= n/a
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program