
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22359 is a Cross-Site Request Forgery (CSRF) vulnerability in the AA-Team WordPress Movies Bulk Importer plugin (also known as "movies importer"). It affects all versions up to and including 1.0, with no official patch currently available. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on November 30, 2025, and published by Patchstack on January 22, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack, NVD).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to validate or verify the origin of state-changing requests made to its movie import functionality. An unauthenticated attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator or privileged user, silently triggers unauthorized actions within the plugin — such as initiating bulk movie imports — without the victim's knowledge or consent. No special privileges are required by the attacker, but user interaction (e.g., clicking a malicious link or visiting a crafted page) is necessary for exploitation (Patchstack, NVD).
Successful exploitation allows a malicious actor to force higher-privileged WordPress users to execute unwanted actions under their current authentication context, primarily affecting integrity. The confidentiality and availability impacts are rated as none, limiting the practical damage to unauthorized data modification or plugin-driven content changes on the affected WordPress site. While the individual impact is low, Patchstack notes that CSRF vulnerabilities of this type are commonly leveraged in mass-exploit campaigns targeting thousands of WordPress sites simultaneously (Patchstack).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified. Patchstack classifies this as low priority with unlikely exploitation, though it notes CSRF vulnerabilities can be used in broad, automated mass-exploit campaigns against WordPress sites (Patchstack, NVD).
/wp-content/plugins/movies-importer/).wp-admin/admin-post.php or wp-admin/admin-ajax.php) with movie import action parameters from unusual referrer URLs or external origins.As of the publication date, no official patch is available for the WordPress Movies Bulk Importer plugin version 1.0 (Patchstack). Site administrators should consider deactivating and removing the plugin until a patched version is released. As a general mitigation, deploying a WordPress security plugin or Web Application Firewall (WAF) — such as Patchstack — that provides virtual patching can block CSRF exploitation attempts without requiring a code-level fix. Administrators should also ensure that privileged users avoid clicking unsolicited links while authenticated to the WordPress dashboard.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."