cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fortemplate-kit-import template-kit-import

Direction: ascending
Jun 07, 2024

Template Kit – Import # CVE-2024-2334

CVE, Research URL

CVE-2024-2334

Date
Apr 10, 2024
Research Description
The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.0.15.
Status
vulnerable
Jul 28, 2026

Template Kit – Import # PSC-2026-64682

PSC, Research URL

PSC-2026-64682

Date
Jul 28, 2026
Research Description
Template import tools bring structured design data and assets into a WordPress installation. Import permissions, file validation, remote resources, and the safety of stored page content all matter before an imported kit reaches the public site. Template Kit - Import version 1.0.16 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64682, confirming that the plugin was reviewed from a secure code perspective with attention to import authorization, package validation, template data, remote assets, stored content, and post-import rendering.
Affected versions
Min 1.0.16, max 1.0.16.
Status
SAFE & CERTIFIED