SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65483

MEDIUM · CVSS 5.9 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The HashThemes Demo Importer versions up to 1.4.2 are vulnerable to a Cross Site Scripting (XSS) attack, allowing attackers to inject malicious scripts into web pages viewed by users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive information. Organizations using this plugin should prioritize patching or upgrading to mitigate potential exploitation risks.

CVE
CVE-2026-65483
Severity
MEDIUM
CVSS
5.9
EPSS
0.17%

Original NVD Description

Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.