PoC Index

CVE-2022-1008

HIGH 7.2EPSS 1.7%

The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.68% chance of exploitation in the next 30 days, 75th percentile
Published
2022-04-11
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related