Description
The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed
Published: 2022-04-11
Score: 7.2 High
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-24358 The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed
History

No history.

Subscriptions

Ocdi One Click Demo Import
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-02T23:47:43.121Z

Reserved: 2022-03-17T00:00:00.000Z

Link: CVE-2022-1008

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-11T15:15:09.030

Modified: 2024-11-21T06:39:50.907

Link: CVE-2022-1008

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses