Executive brief
The HashThemes Demo Importer plugin for WordPress, which helps users import pre-made website designs, contains a security flaw that allows users with 'Author' privileges to inject malicious scripts. If an administrator or another user views the affected content, these scripts could execute, potentially leading to unauthorized actions or the redirection of visitors to malicious websites. This risk is primarily internal, requiring an existing account with high-level permissions to initiate.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the HashThemes Demo Importer plugin for WordPress (versions <= 1.4.2) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Author' or higher privileges to inject malicious JavaScript payloads into the site. Exploitation requires a victim (such as an administrator) to interact with the affected page or perform a specific action. Successful exploitation can lead to session hijacking, unauthorized administrative actions, or site defacement. As of the advisory date, no official patch has been confirmed.
Affected products
- HashThemes HashThemes Demo Importer <= 1.4.2
Timeline
- 2026-01-18: other: Vulnerability reported by researcher Mike Montoya
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date