CVE-2022-29451
29.04.2022, 17:15
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.
Vendor | Product | Version |
---|---|---|
rarathemes | rara_one_click_demo_import | 𝑥 < 1.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References