First published: Mon Apr 11 2022(Updated: )
The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rarathemes Rara One Click Demo Import | <3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1008 is considered a high severity vulnerability due to its ability to allow high privilege users to upload arbitrary files.
To fix CVE-2022-1008, update the One Click Demo Import WordPress plugin to version 3.1.0 or later.
CVE-2022-1008 affects installations of the One Click Demo Import WordPress plugin versions before 3.1.0.
CVE-2022-1008 is a file upload vulnerability that allows arbitrary file uploads by privileged users.
Yes, CVE-2022-1008 can lead to further attacks such as remote code execution if attackers upload malicious files.