PT-2022-13941 · WordPress · Postmagthemes Demo Import

Thunder.God.Hhh

+1

·

Published

2022-12-05

·

Updated

2025-04-23

·

CVE-2022-1540

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PostmagThemes Demo Import WordPress plugin versions 1.0.0 through 1.0.7
Description The issue allows high-privilege users, such as admins, to upload arbitrary files, including PHP files, due to a lack of validation of the imported file. This can lead to remote code execution (RCE).
Recommendations For PostmagThemes Demo Import WordPress plugin versions 1.0.0 through 1.0.7, update to a version later than 1.0.7 to resolve the issue. As a temporary workaround, consider restricting the file upload functionality to prevent arbitrary file uploads until a patch is available.

Exploit

Fix

Related Identifiers

CVE-2022-1540

Affected Products

Postmagthemes Demo Import