The Xylus Themes WP Smart Import plugin for WordPress has a security flaw known as Cross-Site Scripting (XSS). This vulnerability, identified as CVE-2024-32597, could allow an attacker to inject harmful scripts into your website. When visitors browse your site, these scripts could run, potentially leading to issues like unwanted redirects, displaying malicious content, or even stealing sensitive information. This particular issue affects plugin versions up to and including 1.0.7.
CVE Details
- Product Name: Xylus Themes WP Smart Import plugin for WordPress
- CVE ID: CVE-2024-32597
- Published Date: April 18, 2024
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts the Xylus Themes WP Smart Import plugin for WordPress, specifically versions up to and including 1.0.7. If your website uses any version of this plugin that is 1.0.7 or older, it is potentially at risk.
Current Status
This vulnerability has been thoroughly analyzed and publicly disclosed. A patch has been made available by the developers, meaning that users can take concrete steps to secure their websites against this specific threat.
Severity Level
This vulnerability is officially rated with a Medium severity. Although the CVSS score is 5.9, some analyses, such as Patchstack’s, categorize it as “Low priority.” It’s important to understand that successful exploitation typically requires some form of user interaction from a privileged user, like an Author on the WordPress site. This could involve them clicking on a specially crafted malicious link or submitting a form that contains harmful code.
Possible Solutions
Fortunately, a solution is available to mitigate this risk. To protect your WordPress site and its visitors, you should:
- Update Your Plugin: The most crucial step is to immediately update the Xylus Themes WP Smart Import plugin to version 1.1.0 or any later version. This update includes the necessary security fixes to resolve the Cross-Site Scripting (XSS) vulnerability. Always ensure your WordPress plugins are kept up-to-date.
References
- https://patchstack.com/database/vulnerability/wp-smart-import/wordpress-wp-smart-import-plugin-1-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve
- https://patchstack.com/database/vulnerability/wp-smart-import/wordpress-wp-smart-import-plugin-1-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve


