Description
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24836 | The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE. |
References
History
Wed, 23 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T15:05:12.055Z
Reserved: 2022-04-29T14:26:00.458Z
Link: CVE-2022-1540
Updated: 2024-08-03T00:10:03.363Z
Status : Modified
Published: 2022-12-05T17:15:09.780
Modified: 2025-04-23T15:15:47.217
Link: CVE-2022-1540
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD