CVE-2026-65483 MEDIUM

CVE-2026-65483: WordPress HashThemes Demo Importer plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability

Vendor Hashthemes
Product HashThemes Demo Importer
Weakness CWE-79 · XSS
Published July 23, 2026
Last update July 23, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.

Explanation of Vulnerability in Simple Terms

02Summary

HashThemes Demo Importer versions up to 1.4.2 contain a cross-site scripting vulnerability. An authenticated user with high privileges can inject malicious scripts that execute in other users' browsers when they interact with the affected component. The vulnerability requires user interaction to trigger. Impact is limited to low-severity data exposure and site modification.

What an attacker can do

03Attacker Capabilities

Inject malicious scripts that run in other users' browsers to steal data or modify site content.

Potential impact on your site

04Site Impact

High-privilege accounts could be compromised to inject malware or deface your site if tricked into visiting a malicious link.

Conditions required to exploit

05Prerequisites

Attacker must have high-level admin privileges and the victim must visit a page or click a link containing the malicious payload.

Key dates

06Disclosure timeline

July 23, 2026 CVE published

Related vulnerabilities

08Related CVE