Impact
A flaw in the bulk content‑import feature of a popular WordPress plugin allows users with contributor‑level access or higher to bypass authorization checks and use the author identity of the import preset. Under the preset author’s privileges, contributors can inject arbitrary web scripts into newly created posts. The scripts are stored in the database and execute unfiltered whenever anyone views the content, effectively enabling malicious client‑side code execution in the context of visitors to the site.
Affected Systems
The vulnerability is present in all versions of the Content Egg WordPress plugin released before 11.9.0. WordPress sites that have not upgraded to version 11.9.0 or later are susceptible, regardless of the version of WordPress itself. The issue affects any installation where contributor or higher role users have permissions to run bulk import operations.
Risk and Exploitability
Explicit exploitation requires only that the attacker have at least contributor rights and access to the bulk import interface. Because the scripts are stored and executed on page load, the damage can be widespread across all site visitors. The EPSS score is unavailable and the issue is not listed in CISA KEV, but the inherent stored XSS nature and lack of input validation confer a high likelihood of real‑world impact when insider or compromised contributor accounts are present.
OpenCVE Enrichment