Impact
The CSV Importer Improved plugin accepts CSV uploads and, according to the CVE description, fails to neutralize input when generating the web page, allowing attackers to embed malicious JavaScript that is then stored. Once the attacker injects a payload through a crafted CSV file, any site visitor who views a page that displays the imported data would be subjected to the script, enabling typical XSS consequences such as credential theft or defacement.
Affected Systems
The vulnerability affects the WordPress plugin CSV Importer Improved by Jason Judge for all versions up to and including 0.6.1. No specific sub‑version details are provided; any instance running a version ≤0.6.1 is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of <1% suggests a very low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Because the flaw is stored, attackers can exploit it once an authorized user uploads a malicious CSV; the impact is limited to site visitors who see the rendered content. The lack of authentication bypass and the relatively low EPSS reduce urgency, but the potential for session hijacking and data exfiltration warrants timely remediation.
OpenCVE Enrichment
EUVD