Impact
The HashThemes Demo Importer plugin for WordPress, versions 1.4.2 and earlier, contains a cross‑site scripting (XSS) vulnerability. Unsanitised input processed by the plugin allows an attacker to inject and execute arbitrary JavaScript in the browsers of users who view affected content. This is a CWE‑79 weakness that can be triggered when the plugin handles user‑supplied data.
Affected Systems
All WordPress sites that have the HashThemes Demo Importer plugin version 1.4.2 or older are affected. The plugin is distributed by hashthemes and is named HashThemes Demo Importer. Upgrading to a more recent release removes the flaw.
Risk and Exploitability
The CVSS score of 5.9 classifies the vulnerability as moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at the time of assessment. The flaw is not listed in the CISA KEV catalog. Exploitation appears to involve injecting malicious input through the plugin’s import interface, but the CVE description does not specify whether authentication is required or whether the import pages are publicly accessible, so the exact attack surface remains uncertain.
OpenCVE Enrichment