CyberRota Analysis
AI-GeneratedThe HashThemes Demo Importer versions up to 1.4.2 are vulnerable to a Cross Site Scripting (XSS) attack, allowing attackers to inject malicious scripts into web pages viewed by users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive information. Organizations using this plugin should prioritize patching or upgrading to mitigate potential exploitation risks.
CVE
CVE-2026-65483
Severity
MEDIUM
CVSS
5.9
EPSS
0.17%
Original NVD Description
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.