Description
Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images import-cdn-remote-images allows Stored XSS.This issue affects Import CDN-Remote Images: from n/a through <= 2.1.2.
Published: 2025-07-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Import CDN-Remote Images plugin allows an attacker to perform a cross‑site request forgery that results in stored cross‑site scripting. The flaw exists because the plugin accepts arbitrary remote image URLs and does not protect the action with a proper nonce or authentication guard. An attacker can craft a malicious request that, when executed by an authenticated administrator or user, stores a script payload in the media gallery. When the attacker’s script is later rendered on the site, it runs with the privileges of the user who views the page, enabling defacement, data theft or session hijacking. This flaw is identified as CWE‑352.

Affected Systems

The issue affects the Atakan Au Import CDN‑Remote Images WordPress plugin with any release up to and including 2.1.2. Sites using any earlier unreleased or experimental releases are also impacted. The vulnerability flows through the plugin’s import functionality which accepts remote CDN URLs from any user who can trigger a request to the plugin’s import endpoint.

Risk and Exploitability

The CVSS score of 7.1 places this vulnerability in the high‑severity range, indicating significant potential impact if exploited. The EPSS score of less than 1% suggests that, at this time, the likelihood of a coordinated exploitation effort is low, and it is not listed in the CISA KEV catalog. However, the attack vector is the attacker’s ability to host a malicious file on a CDN and induce an authenticated user to trigger its import, a scenario that requires the victim to be logged into the WordPress installation. Because the flaw allows the injection of arbitrary JavaScript, the damage could be widespread if the attacker successfully compromises a privileged user or any user with write access. The risk is therefore significant for sites that deploy the plugin without a recent update and for which administrators or contributors can access the import function.

Generated by OpenCVE AI on April 30, 2026 at 09:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Import CDN‑Remote Images plugin to the latest available release (>= 2.1.3) to eliminate the CSRF and stored XSS issue.
  • If an immediate update is not possible, temporarily restrict the import functionality to administrators only by adjusting user capabilities or configuring a restrictive role set.
  • Disable the plugin entirely on sites that do not rely on remote CDN imports until the update becomes available.

Generated by OpenCVE AI on April 30, 2026 at 09:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21647 Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images allows Stored XSS. This issue affects Import CDN-Remote Images: from n/a through 2.1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images allows Stored XSS. This issue affects Import CDN-Remote Images: from n/a through 2.1.2. Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images import-cdn-remote-images allows Stored XSS.This issue affects Import CDN-Remote Images: from n/a through <= 2.1.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 16 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00032}


Wed, 16 Jul 2025 10:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images allows Stored XSS. This issue affects Import CDN-Remote Images: from n/a through 2.1.2.
Title WordPress Import CDN-Remote Images plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:52.793Z

Reserved: 2025-05-15T18:02:03.510Z

Link: CVE-2025-48153

cve-icon Vulnrichment

Updated: 2025-07-16T20:18:49.482Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T11:15:24.263

Modified: 2026-04-23T15:30:53.687

Link: CVE-2025-48153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:45:25Z

Weaknesses