Vulnerabilities and security researches fortemplate-kit-import template-kit-import
Direction: ascendingJun 07, 2024
Template Kit – Import # CVE-2024-2334
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 10, 2024
- Research Description
- The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.0.15.
- Status
-
vulnerable
Jul 28, 2026
Template Kit – Import # PSC-2026-64682
- PSC, Research URL
- Home page URL
- Application
- Date
- Jul 28, 2026
- Research Description
- Template import tools bring structured design data and assets into a WordPress installation. Import permissions, file validation, remote resources, and the safety of stored page content all matter before an imported kit reaches the public site. Template Kit - Import version 1.0.16 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64682, confirming that the plugin was reviewed from a secure code perspective with attention to import authorization, package validation, template data, remote assets, stored content, and post-import rendering.
- Affected versions
-
Min 1.0.16, max 1.0.16.
- Status
-
SAFE & CERTIFIED