CVE-2022-29451: WordPress Rara One Click Demo Import plugin <= 1.2.9 - Cross-Site Request Forgery (CSRF) leads to Arbitrary File Upload vulnerability
Published Apr 29, 2022
·Updated
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.
Affected Software
1 affected component
Rarathemes Rara One Click Demo Import Wordpress<1.3.0
Remediation
Information
Deactivate and delete. No response from the vendor.
Event History
Apr 29, 2022
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-29451?
CVE-2022-29451 is considered a high severity vulnerability due to its ability to allow arbitrary file uploads.
2
How do I fix CVE-2022-29451?
To fix CVE-2022-29451, update the Rara One Click Demo Import plugin to version 1.3.0 or later.
3
What type of vulnerability is CVE-2022-29451?
CVE-2022-29451 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What could an attacker potentially do with CVE-2022-29451?
An attacker could trick a logged-in admin user into uploading dangerous files, compromising the WordPress site.
5
Which versions of Rara One Click Demo Import are affected by CVE-2022-29451?
CVE-2022-29451 affects Rara One Click Demo Import plugin versions 1.2.9 and earlier.