CVE-2022-23976: WordPress Access Demo Importer plugin <= 1.0.7 - Cross-Site Request Forgery (CSRF) vulnerability leading to Data Reset (Posts / Pages / Media)
Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-23976?
CVE-2022-23976 is a Cross-Site Request Forgery (CSRF) vulnerability in Access Demo Importer plugin, version 1.0.7 or earlier, on WordPress.
How does CVE-2022-23976 impact WordPress sites?
CVE-2022-23976 can allow an attacker to reset all data, including posts, pages, and media.
What is the severity level of CVE-2022-23976?
CVE-2022-23976 has a severity level of 8.1 (high).
How can I fix CVE-2022-23976?
To fix CVE-2022-23976, it is recommended to update Access Demo Importer plugin to version 1.0.8 or later.
Where can I find more information about CVE-2022-23976?
You can find more information about CVE-2022-23976 in the reference links: [link1](https://patchstack.com/database/vulnerability/access-demo-importer/wordpress-access-demo-importer-plugin-1-0-7-cross-site-request-forgery-csrf-vulnerability-leading-to-data-reset-posts-pages-media) and [link2](https://wordpress.org/plugins/access-demo-importer/#developers).