PT-2022-13589 · WordPress · One Click Demo Import

Yicheng Liu

·

Published

2022-04-11

·

Updated

2022-04-15

·

CVE-2022-1008

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions One Click Demo Import WordPress plugin versions prior to 3.1.0
Description The issue allows high privilege users, such as admins, to upload arbitrary files, including PHP files, even when FILE MODS and FILE EDIT are disallowed, due to a lack of validation of the imported file.
Recommendations For versions prior to 3.1.0, update to version 3.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the FILE MODS and FILE EDIT permissions to minimize the risk of exploitation. Additionally, restrict access to the file import functionality to prevent high privilege users from uploading arbitrary files.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1008

Affected Products

One Click Demo Import