Vulnerability Description
The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ocdi | One Click Demo Import | < 3.1.0 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2695999PatchThird Party Advisory
- https://wpscan.com/vulnerability/0c2e2b4d-49eb-4fd9-b9f0-3feae80c1082ExploitPatchThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2695999PatchThird Party Advisory
- https://wpscan.com/vulnerability/0c2e2b4d-49eb-4fd9-b9f0-3feae80c1082ExploitPatchThird Party Advisory
FAQ
What is CVE-2022-1008?
CVE-2022-1008 is a vulnerability with a CVSS score of 7.2 (HIGH). The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and...
How severe is CVE-2022-1008?
CVE-2022-1008 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1008?
Check the references section above for vendor advisories and patch information. Affected products include: Ocdi One Click Demo Import.