CVE · High

CVE-2022-23976 — Access Demo Importer [access-demo-importer] < 1.0.8 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-23976 Access Demo Importer [access-demo-importer] < 1.0.8 (closed) Cross-Site Request Forgery (CSRF) High 8.1 < 1.0.8 1.0.8 2022-01-24

CVE-2022-23976

The Access Demo Importer plugin for WordPress through version 1.0.7 contains a Cross-Site Request Forgery vulnerability in its AJAX handler for the `adi_demo_data_reset` function because it fails to verify nonce tokens. An attacker can exploit this flaw to trick users into resetting all site data, including posts, pages, and media files. The vulnerability was fixed in version 1.0.8.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.