Description
Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah Import Users to MailChimp import-users-to-mailchimp allows Stored XSS.This issue affects Import Users to MailChimp: from n/a through <= 1.0.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery that permits an attacker to inject malicious scripts that are stored on the site. An attacker who can forge a request that bypasses the plugin’s CSRF protection can cause the plugin to save a payload that will execute in the browsers of any user who views the affected content, potentially enabling credential theft, session hijacking, or defacement. The weakness is identified as CWE‑352. No evidence of exploitation in the wild is known, but the flaw allows persistent attacker control of the site’s front end.

Affected Systems

WordPress users running the Import Users to MailChimp plugin by Sana Ullah, any version up to and including 1.0. The issue exists for all installations that have this plugin active, regardless of the WordPress core version.

Risk and Exploitability

The likely attack vector is a forged request initiated by an unsuspecting user clicking a malicious link, inferred from the CVE description that the flaw is a CSRF vulnerability permitting stored XSS. The CVSS score of 7.1 reflects a moderate‑to‑high severity due to impact on confidentiality, integrity, and availability. The EPSS score of < 1 % indicates that the probability of exploitation is low at the time of analysis, and the vulnerability is not yet listed in the CISA KEV catalog. However, the lack of CSRF safeguards means that an attacker with a phishable link or ability to trick a user into visiting a crafted URL could achieve the exploit in a relatively straightforward manner. Therefore, while the overall risk is tempered by low exploitation probability, the potential damage warrants prompt action.

Generated by OpenCVE AI on May 2, 2026 at 06:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Import Users to MailChimp plugin to the latest available version (1.1 or newer).
  • If an upgrade is not immediately possible, disable or delete the plugin to eliminate the attack surface.
  • Consider implementing an additional CSRF token or security‑through‑design plugin to enforce request integrity on all WordPress administrative pages.

Generated by OpenCVE AI on May 2, 2026 at 06:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3334 Cross-Site Request Forgery (CSRF) vulnerability in SandyIN Import Users to MailChimp allows Stored XSS.This issue affects Import Users to MailChimp: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in SandyIN Import Users to MailChimp allows Stored XSS.This issue affects Import Users to MailChimp: from n/a through 1.0. Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah Import Users to MailChimp import-users-to-mailchimp allows Stored XSS.This issue affects Import Users to MailChimp: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in SandyIN Import Users to MailChimp allows Stored XSS.This issue affects Import Users to MailChimp: from n/a through 1.0.
Title WordPress Import Users to MailChimp plugin <= 1.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:16.953Z

Reserved: 2025-01-16T11:28:07.194Z

Link: CVE-2025-23675

cve-icon Vulnrichment

Updated: 2025-01-17T17:19:52.745Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:43.753

Modified: 2026-06-17T08:56:17.883

Link: CVE-2025-23675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:15:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)