PT-2024-11509 · WordPress · Theme Demo Import

Ccltt1201

·

Published

2024-01-16

·

Updated

2024-01-19

·

CVE-2022-1538

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Theme Demo Import WordPress plugin versions prior to 1.1.1
Description The issue allows high-privilege users, such as admins, to upload arbitrary files, including PHP files, even when FILE MODS and FILE EDIT are disallowed, due to a lack of validation of the imported file.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the file import feature to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1538

Affected Products

Theme Demo Import