QID 730784
Date Published: 2023-04-12
QID 730784: WordPress Plugin One Click Demo Import Arbitrary File Upload Vulnerability
One Click Demo Import is vulnerable to arbitrary file upload vulnerability.
The plugin does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed
Affected Versions:
One Click Demo Import WordPress plugin versions prior to 3.1.0
QID Detection Logic(Unauthenticated): This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the One Click Demo Import plugin.
Successful exploitation of this vulnerability may allowing high privilege users such as admin to upload arbitrary files.
Solution
Customers are advised to install One Click Demo Import or later version to remediate this vulnerability.
Vendor References
- One Click Demo Import Plugin Release Notes -
wordpress.org/plugins/one-click-demo-import/#developers
CVEs related to QID 730784
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| One Click Demo Import Plugin Release Notes |
|